Add terraform-provider-gpgvaultsecret
A terraform-plugin-framework provider for the vault-plugin-secrets-gpg engine, managing engine mounts and OpenPGP keys on Vault/OpenBao. - gpg_secret_backend resource: mount the engine (+ optional plugin catalog registration when a sha256 is given; deregisters on destroy). - gpg_key resource: create/configure a key (algorithm, identity, exportable, deletion_allowed, min_decryption_version); computed public_key/fingerprint/ key_id/latest_version; destroy auto-enables deletion; import <backend>/<name>. - gpg_key data source: read a key's metadata + armored public key. - Talks to Vault/OpenBao via hashicorp/vault/api; address/token fall back to VAULT_ADDR/VAULT_TOKEN. Unit tests plus an e2e running real terraform apply/destroy against a Vault dev server + the gpg plugin. Release publishes a zip to the artifactapi terraform-unkin registry on v* tags.
This commit is contained in:
+14
@@ -0,0 +1,14 @@
|
||||
/terraform-provider-gpgvaultsecret
|
||||
*.zip
|
||||
*.out
|
||||
*.test
|
||||
dist/
|
||||
.terraform/
|
||||
.terraform.lock.hcl
|
||||
*.tfstate
|
||||
*.tfstate.backup
|
||||
.env
|
||||
|
||||
# e2e artifacts
|
||||
test/plugins/
|
||||
test/dev.tfrc
|
||||
@@ -0,0 +1,15 @@
|
||||
repos:
|
||||
- repo: https://github.com/pre-commit/pre-commit-hooks
|
||||
rev: v5.0.0
|
||||
hooks:
|
||||
- id: trailing-whitespace
|
||||
- id: end-of-file-fixer
|
||||
- id: check-yaml
|
||||
- id: check-added-large-files
|
||||
|
||||
- repo: https://github.com/dnephin/pre-commit-golang
|
||||
rev: v0.5.1
|
||||
hooks:
|
||||
- id: go-fmt
|
||||
- id: go-vet
|
||||
- id: go-mod-tidy
|
||||
@@ -0,0 +1,18 @@
|
||||
when:
|
||||
- event: pull_request
|
||||
|
||||
steps:
|
||||
- name: build
|
||||
image: golang:1.25
|
||||
commands:
|
||||
- make build
|
||||
backend_options:
|
||||
kubernetes:
|
||||
serviceAccountName: default
|
||||
resources:
|
||||
requests:
|
||||
memory: 512Mi
|
||||
cpu: 1
|
||||
limits:
|
||||
memory: 2Gi
|
||||
cpu: 2
|
||||
@@ -0,0 +1,18 @@
|
||||
when:
|
||||
- event: pull_request
|
||||
|
||||
steps:
|
||||
- name: pre-commit
|
||||
image: git.unkin.net/unkin/almalinux9-gobuilder:20260606
|
||||
commands:
|
||||
- uvx pre-commit run --all-files
|
||||
backend_options:
|
||||
kubernetes:
|
||||
serviceAccountName: default
|
||||
resources:
|
||||
requests:
|
||||
memory: 512Mi
|
||||
cpu: 1
|
||||
limits:
|
||||
memory: 2Gi
|
||||
cpu: 2
|
||||
@@ -0,0 +1,40 @@
|
||||
when:
|
||||
- event: tag
|
||||
|
||||
steps:
|
||||
- name: package
|
||||
image: git.unkin.net/unkin/almalinux9-gobuilder:20260606
|
||||
commands:
|
||||
- make package VERSION=${CI_COMMIT_TAG}
|
||||
backend_options:
|
||||
kubernetes:
|
||||
serviceAccountName: default
|
||||
resources:
|
||||
requests:
|
||||
memory: 512Mi
|
||||
cpu: 1
|
||||
limits:
|
||||
memory: 2Gi
|
||||
cpu: 2
|
||||
|
||||
- name: upload
|
||||
image: git.unkin.net/unkin/almalinux9-base:20260606
|
||||
commands:
|
||||
- |
|
||||
VERSION=$$(echo ${CI_COMMIT_TAG} | sed 's/^v//')
|
||||
FILE="terraform-provider-gpgvaultsecret_$${VERSION}_linux_amd64.zip"
|
||||
curl -f -X PUT \
|
||||
"https://artifactapi.k8s.syd1.au.unkin.net/api/v2/remotes/terraform-unkin/files/unkin/gpgvaultsecret/$${FILE}" \
|
||||
-H "Content-Type: application/zip" \
|
||||
--data-binary @"$${FILE}"
|
||||
depends_on: [package]
|
||||
backend_options:
|
||||
kubernetes:
|
||||
serviceAccountName: default
|
||||
resources:
|
||||
requests:
|
||||
memory: 128Mi
|
||||
cpu: 100m
|
||||
limits:
|
||||
memory: 512Mi
|
||||
cpu: 500m
|
||||
@@ -0,0 +1,33 @@
|
||||
when:
|
||||
- event: pull_request
|
||||
|
||||
steps:
|
||||
- name: lint
|
||||
image: golang:1.25
|
||||
commands:
|
||||
- make lint
|
||||
backend_options:
|
||||
kubernetes:
|
||||
serviceAccountName: default
|
||||
resources:
|
||||
requests:
|
||||
memory: 512Mi
|
||||
cpu: 1
|
||||
limits:
|
||||
memory: 2Gi
|
||||
cpu: 2
|
||||
|
||||
- name: test
|
||||
image: golang:1.25
|
||||
commands:
|
||||
- make test
|
||||
backend_options:
|
||||
kubernetes:
|
||||
serviceAccountName: default
|
||||
resources:
|
||||
requests:
|
||||
memory: 512Mi
|
||||
cpu: 1
|
||||
limits:
|
||||
memory: 2Gi
|
||||
cpu: 2
|
||||
@@ -0,0 +1,65 @@
|
||||
.PHONY: build install test lint fmt clean tidy package e2e patch minor major check-go
|
||||
|
||||
BINARY := terraform-provider-gpgvaultsecret
|
||||
VERSION ?= $(shell git describe --tags --always --dirty 2>/dev/null || echo "0.0.0-dev")
|
||||
OS_ARCH := linux_amd64
|
||||
INSTALL_VERSION := $(shell echo $(VERSION) | sed 's/^v//')
|
||||
INSTALL_DIR := ~/.terraform.d/plugins/git.unkin.net/unkin/gpgvaultsecret/$(INSTALL_VERSION)/$(OS_ARCH)
|
||||
ZIP := $(BINARY)_$(INSTALL_VERSION)_$(OS_ARCH).zip
|
||||
|
||||
GO_VERSION_REQUIRED := 1.25
|
||||
GO_VERSION_ACTUAL := $(shell go version | sed 's/go version go\([0-9]*\.[0-9]*\).*/\1/')
|
||||
|
||||
check-go:
|
||||
@if [ "$$(printf '%s\n%s' "$(GO_VERSION_REQUIRED)" "$(GO_VERSION_ACTUAL)" | sort -V | head -1)" != "$(GO_VERSION_REQUIRED)" ]; then \
|
||||
echo "ERROR: Go >= $(GO_VERSION_REQUIRED) required, found $(GO_VERSION_ACTUAL)"; exit 1; \
|
||||
fi
|
||||
|
||||
build: check-go tidy
|
||||
go build -ldflags="-s -w -X main.version=$(VERSION)" -o $(BINARY)
|
||||
|
||||
install: build
|
||||
mkdir -p $(INSTALL_DIR)
|
||||
cp $(BINARY) $(INSTALL_DIR)/
|
||||
|
||||
test: check-go
|
||||
go test -race -count=1 ./...
|
||||
|
||||
lint: check-go
|
||||
go vet ./...
|
||||
|
||||
fmt: check-go
|
||||
gofmt -w .
|
||||
|
||||
package: build
|
||||
cp $(BINARY) $(BINARY)_v$(INSTALL_VERSION)
|
||||
python3 -c "import zipfile,sys; z=zipfile.ZipFile(sys.argv[1],'w',zipfile.ZIP_DEFLATED); z.write(sys.argv[2]); z.close()" $(ZIP) $(BINARY)_v$(INSTALL_VERSION)
|
||||
rm $(BINARY)_v$(INSTALL_VERSION)
|
||||
|
||||
# End-to-end: boots Vault + LiteLLM + the plugin and applies real terraform.
|
||||
e2e:
|
||||
./scripts/e2e.sh
|
||||
|
||||
clean:
|
||||
rm -f $(BINARY) *.zip
|
||||
|
||||
tidy:
|
||||
go mod tidy
|
||||
|
||||
_LATEST := $(shell git tag --sort=-v:refname | grep -E '^v[0-9]+\.[0-9]+\.[0-9]+$$' | head -1)
|
||||
_BASE := $(if $(_LATEST),$(_LATEST),v0.0.0)
|
||||
_MAJ := $(shell echo $(_BASE) | sed 's/^v//' | cut -d. -f1)
|
||||
_MIN := $(shell echo $(_BASE) | sed 's/^v//' | cut -d. -f2)
|
||||
_PAT := $(shell echo $(_BASE) | sed 's/^v//' | cut -d. -f3)
|
||||
|
||||
patch:
|
||||
@NEW=v$(_MAJ).$(_MIN).$(shell expr $(_PAT) + 1); \
|
||||
git tag $$NEW && echo "Tagged $$NEW" && git push origin $$NEW
|
||||
|
||||
minor:
|
||||
@NEW=v$(_MAJ).$(shell expr $(_MIN) + 1).0; \
|
||||
git tag $$NEW && echo "Tagged $$NEW" && git push origin $$NEW
|
||||
|
||||
major:
|
||||
@NEW=v$(shell expr $(_MAJ) + 1).0.0; \
|
||||
git tag $$NEW && echo "Tagged $$NEW" && git push origin $$NEW
|
||||
@@ -1,3 +1,96 @@
|
||||
# terraform-provider-gpgvaultsecret
|
||||
|
||||
Terraform provider for the Vault/OpenBao GPG/OpenPGP secrets engine (gpgvaultsecret) — manage backends and keys
|
||||
A Terraform/OpenTofu provider for the
|
||||
[vault-plugin-secrets-gpg](https://git.unkin.net/unkin/vault-plugin-secrets-gpg)
|
||||
engine. It manages the engine **mount** (and, optionally, plugin catalog
|
||||
registration) and **OpenPGP keys** on HashiCorp Vault or OpenBao.
|
||||
|
||||
The provider's source address is `git.unkin.net/unkin/gpgvaultsecret`; its
|
||||
resources are prefixed `gpg_` (declare it under the local name `gpg`).
|
||||
|
||||
## Resources & data sources
|
||||
|
||||
| Type | Purpose |
|
||||
|------|---------|
|
||||
| `gpg_secret_backend` (resource) | Mount the gpg engine at a path. When `sha256` is set, register the plugin in the catalog first. |
|
||||
| `gpg_key` (resource) | Create and configure an OpenPGP key (algorithm, identity, exportable, deletion, min decryption version); exposes the armored public key, fingerprint, key id and latest version. |
|
||||
| `gpg_key` (data source) | Read an existing key's metadata + armored public key. |
|
||||
|
||||
## Usage
|
||||
|
||||
```hcl
|
||||
terraform {
|
||||
required_providers {
|
||||
gpg = {
|
||||
source = "artifactapi.k8s.syd1.au.unkin.net/terraform-unkin/gpgvaultsecret"
|
||||
}
|
||||
}
|
||||
}
|
||||
|
||||
provider "gpg" {
|
||||
# address and token fall back to VAULT_ADDR / VAULT_TOKEN
|
||||
address = "https://vault.main.unkin.net"
|
||||
}
|
||||
|
||||
# Mount the engine. Omit sha256 if the plugin is already registered out of band
|
||||
# (e.g. by terraform-vault). Set it to have this resource register the plugin.
|
||||
resource "gpg_secret_backend" "gpg" {
|
||||
path = "gpg"
|
||||
description = "GPG/OpenPGP secrets engine"
|
||||
# sha256 = "0e92d7408795688badb55789bc1604e8f1dd4d71998656c7f831991fce9a7b20"
|
||||
}
|
||||
|
||||
resource "gpg_key" "app" {
|
||||
backend = gpg_secret_backend.gpg.path
|
||||
name = "app"
|
||||
algorithm = "rsa-4096" # rsa-2048 | rsa-3072 | rsa-4096 | ed25519
|
||||
identity = "App <app@unkin.net>"
|
||||
}
|
||||
|
||||
# Wire the armored public key somewhere (e.g. a pass store, a k8s secret).
|
||||
output "app_public_key" {
|
||||
value = gpg_key.app.public_key
|
||||
}
|
||||
```
|
||||
|
||||
### `gpg_secret_backend`
|
||||
|
||||
| Attribute | | Description |
|
||||
|-----------|-----|-------------|
|
||||
| `path` | required, force-new | Mount path (e.g. `gpg`). |
|
||||
| `plugin` | optional, force-new | Registered plugin name/mount type. Default `vault-plugin-secrets-gpg`. |
|
||||
| `description` | optional | Mount description. |
|
||||
| `sha256` | optional | If set, (re)register the plugin in the catalog with this binary hash before mounting. |
|
||||
| `command` | optional | Binary filename in the server `plugin_directory` used for registration. Defaults to `plugin`. |
|
||||
|
||||
Import: `terraform import gpg_secret_backend.gpg gpg`.
|
||||
|
||||
### `gpg_key`
|
||||
|
||||
| Attribute | | Description |
|
||||
|-----------|-----|-------------|
|
||||
| `backend` | required, force-new | Mount path of the engine. |
|
||||
| `name` | required, force-new | Key name. |
|
||||
| `algorithm` | optional, force-new | `rsa-2048` / `rsa-3072` (default) / `rsa-4096` / `ed25519`. |
|
||||
| `identity` | optional, force-new | OpenPGP User ID. Defaults to the key name. |
|
||||
| `exportable` | optional | Allow private-key export (enable-only). |
|
||||
| `deletion_allowed` | optional | Whether the key may be deleted. `terraform destroy` enables this automatically. |
|
||||
| `min_decryption_version` | optional | Minimum version usable for decrypt/verify. |
|
||||
| `latest_version`, `fingerprint`, `key_id`, `public_key` | computed | Current key material metadata. |
|
||||
|
||||
Import: `terraform import gpg_key.app gpg/app`.
|
||||
|
||||
## Build
|
||||
|
||||
```sh
|
||||
make build # -> terraform-provider-gpgvaultsecret
|
||||
make install # into ~/.terraform.d/plugins/... for local use
|
||||
make test # go test -race (unit tests; no Vault needed)
|
||||
make e2e # real terraform apply/destroy against a Vault dev server + the gpg plugin
|
||||
make package # zip for the artifactapi terraform registry
|
||||
```
|
||||
|
||||
CI (Woodpecker) runs pre-commit/build/lint/test on PRs. On a `v*` tag it builds
|
||||
and PUTs `terraform-provider-gpgvaultsecret_<version>_linux_amd64.zip` to the
|
||||
artifactapi `terraform-unkin` registry (GPG-signed server-side), installable via
|
||||
the bare `source = "artifactapi.k8s.syd1.au.unkin.net/terraform-unkin/gpgvaultsecret"`.
|
||||
|
||||
@@ -0,0 +1,9 @@
|
||||
data "gpg_key" "app" {
|
||||
backend = "gpg"
|
||||
name = "app"
|
||||
}
|
||||
|
||||
# e.g. import into a pass store or hand to another system
|
||||
output "app_public_key" {
|
||||
value = data.gpg_key.app.public_key
|
||||
}
|
||||
@@ -0,0 +1,15 @@
|
||||
resource "gpg_key" "app" {
|
||||
backend = "gpg"
|
||||
name = "app"
|
||||
algorithm = "rsa-4096" # rsa-2048 | rsa-3072 | rsa-4096 | ed25519
|
||||
identity = "App <app@unkin.net>"
|
||||
exportable = false
|
||||
}
|
||||
|
||||
output "app_public_key" {
|
||||
value = gpg_key.app.public_key
|
||||
}
|
||||
|
||||
output "app_fingerprint" {
|
||||
value = gpg_key.app.fingerprint
|
||||
}
|
||||
@@ -0,0 +1,9 @@
|
||||
resource "gpg_secret_backend" "gpg" {
|
||||
path = "gpg"
|
||||
description = "GPG/OpenPGP secrets engine"
|
||||
|
||||
# Optional: have this resource register the plugin in the catalog. Omit if the
|
||||
# plugin is already registered (e.g. by terraform-vault).
|
||||
# sha256 = "0e92d7408795688badb55789bc1604e8f1dd4d71998656c7f831991fce9a7b20"
|
||||
# command = "vault-plugin-secrets-gpg"
|
||||
}
|
||||
@@ -0,0 +1,49 @@
|
||||
module git.unkin.net/unkin/terraform-provider-gpgvaultsecret
|
||||
|
||||
go 1.25
|
||||
|
||||
require (
|
||||
github.com/hashicorp/terraform-plugin-framework v1.15.0
|
||||
github.com/hashicorp/vault/api v1.15.0
|
||||
)
|
||||
|
||||
require (
|
||||
github.com/cenkalti/backoff/v4 v4.3.0 // indirect
|
||||
github.com/fatih/color v1.16.0 // indirect
|
||||
github.com/go-jose/go-jose/v4 v4.0.4 // indirect
|
||||
github.com/golang/protobuf v1.5.4 // indirect
|
||||
github.com/hashicorp/errwrap v1.1.0 // indirect
|
||||
github.com/hashicorp/go-cleanhttp v0.5.2 // indirect
|
||||
github.com/hashicorp/go-hclog v1.6.3 // indirect
|
||||
github.com/hashicorp/go-multierror v1.1.1 // indirect
|
||||
github.com/hashicorp/go-plugin v1.6.3 // indirect
|
||||
github.com/hashicorp/go-retryablehttp v0.7.7 // indirect
|
||||
github.com/hashicorp/go-rootcerts v1.0.2 // indirect
|
||||
github.com/hashicorp/go-secure-stdlib/parseutil v0.1.6 // indirect
|
||||
github.com/hashicorp/go-secure-stdlib/strutil v0.1.2 // indirect
|
||||
github.com/hashicorp/go-sockaddr v1.0.2 // indirect
|
||||
github.com/hashicorp/go-uuid v1.0.3 // indirect
|
||||
github.com/hashicorp/hcl v1.0.0 // indirect
|
||||
github.com/hashicorp/terraform-plugin-go v0.27.0 // indirect
|
||||
github.com/hashicorp/terraform-plugin-log v0.9.0 // indirect
|
||||
github.com/hashicorp/terraform-registry-address v0.2.5 // indirect
|
||||
github.com/hashicorp/terraform-svchost v0.1.1 // indirect
|
||||
github.com/hashicorp/yamux v0.1.1 // indirect
|
||||
github.com/mattn/go-colorable v0.1.13 // indirect
|
||||
github.com/mattn/go-isatty v0.0.20 // indirect
|
||||
github.com/mitchellh/go-homedir v1.1.0 // indirect
|
||||
github.com/mitchellh/go-testing-interface v1.14.1 // indirect
|
||||
github.com/mitchellh/mapstructure v1.5.0 // indirect
|
||||
github.com/oklog/run v1.0.0 // indirect
|
||||
github.com/ryanuber/go-glob v1.0.0 // indirect
|
||||
github.com/vmihailenco/msgpack/v5 v5.4.1 // indirect
|
||||
github.com/vmihailenco/tagparser/v2 v2.0.0 // indirect
|
||||
golang.org/x/crypto v0.37.0 // indirect
|
||||
golang.org/x/net v0.39.0 // indirect
|
||||
golang.org/x/sys v0.32.0 // indirect
|
||||
golang.org/x/text v0.24.0 // indirect
|
||||
golang.org/x/time v0.0.0-20200416051211-89c76fbcd5d1 // indirect
|
||||
google.golang.org/genproto/googleapis/rpc v0.0.0-20250218202821-56aae31c358a // indirect
|
||||
google.golang.org/grpc v1.72.1 // indirect
|
||||
google.golang.org/protobuf v1.36.6 // indirect
|
||||
)
|
||||
@@ -0,0 +1,147 @@
|
||||
github.com/armon/go-radix v0.0.0-20180808171621-7fddfc383310/go.mod h1:ufUuZ+zHj4x4TnLV4JWEpy2hxWSpsRywHrMgIH9cCH8=
|
||||
github.com/bgentry/speakeasy v0.1.0/go.mod h1:+zsyZBPWlz7T6j88CTgSN5bM796AkVf0kBD4zp0CCIs=
|
||||
github.com/bufbuild/protocompile v0.4.0 h1:LbFKd2XowZvQ/kajzguUp2DC9UEIQhIq77fZZlaQsNA=
|
||||
github.com/bufbuild/protocompile v0.4.0/go.mod h1:3v93+mbWn/v3xzN+31nwkJfrEpAUwp+BagBSZWx+TP8=
|
||||
github.com/cenkalti/backoff/v4 v4.3.0 h1:MyRJ/UdXutAwSAT+s3wNd7MfTIcy71VQueUuFK343L8=
|
||||
github.com/cenkalti/backoff/v4 v4.3.0/go.mod h1:Y3VNntkOUPxTVeUxJ/G5vcM//AlwfmyYozVcomhLiZE=
|
||||
github.com/davecgh/go-spew v1.1.0/go.mod h1:J7Y8YcW2NihsgmVo/mv3lAwl/skON4iLHjSsI+c5H38=
|
||||
github.com/davecgh/go-spew v1.1.1 h1:vj9j/u1bqnvCEfJOwUhtlOARqs3+rkHYY13jYWTU97c=
|
||||
github.com/davecgh/go-spew v1.1.1/go.mod h1:J7Y8YcW2NihsgmVo/mv3lAwl/skON4iLHjSsI+c5H38=
|
||||
github.com/fatih/color v1.7.0/go.mod h1:Zm6kSWBoL9eyXnKyktHP6abPY2pDugNf5KwzbycvMj4=
|
||||
github.com/fatih/color v1.13.0/go.mod h1:kLAiJbzzSOZDVNGyDpeOxJ47H46qBXwg5ILebYFFOfk=
|
||||
github.com/fatih/color v1.16.0 h1:zmkK9Ngbjj+K0yRhTVONQh1p/HknKYSlNT+vZCzyokM=
|
||||
github.com/fatih/color v1.16.0/go.mod h1:fL2Sau1YI5c0pdGEVCbKQbLXB6edEj1ZgiY4NijnWvE=
|
||||
github.com/go-jose/go-jose/v4 v4.0.4 h1:VsjPI33J0SB9vQM6PLmNjoHqMQNGPiZ0rHL7Ni7Q6/E=
|
||||
github.com/go-jose/go-jose/v4 v4.0.4/go.mod h1:NKb5HO1EZccyMpiZNbdUw/14tiXNyUJh188dfnMCAfc=
|
||||
github.com/go-logr/logr v1.4.2 h1:6pFjapn8bFcIbiKo3XT4j/BhANplGihG6tvd+8rYgrY=
|
||||
github.com/go-logr/logr v1.4.2/go.mod h1:9T104GzyrTigFIr8wt5mBrctHMim0Nb2HLGrmQ40KvY=
|
||||
github.com/go-logr/stdr v1.2.2 h1:hSWxHoqTgW2S2qGc0LTAI563KZ5YKYRhT3MFKZMbjag=
|
||||
github.com/go-logr/stdr v1.2.2/go.mod h1:mMo/vtBO5dYbehREoey6XUKy/eSumjCCveDpRre4VKE=
|
||||
github.com/go-test/deep v1.0.2 h1:onZX1rnHT3Wv6cqNgYyFOOlgVKJrksuCMCRvJStbMYw=
|
||||
github.com/go-test/deep v1.0.2/go.mod h1:wGDj63lr65AM2AQyKZd/NYHGb0R+1RLqB8NKt3aSFNA=
|
||||
github.com/golang/protobuf v1.5.4 h1:i7eJL8qZTpSEXOPTxNKhASYpMn+8e5Q6AdndVa1dWek=
|
||||
github.com/golang/protobuf v1.5.4/go.mod h1:lnTiLA8Wa4RWRcIUkrtSVa5nRhsEGBg48fD6rSs7xps=
|
||||
github.com/google/go-cmp v0.7.0 h1:wk8382ETsv4JYUZwIsn6YpYiWiBsYLSJiTsyBybVuN8=
|
||||
github.com/google/go-cmp v0.7.0/go.mod h1:pXiqmnSA92OHEEa9HXL2W4E7lf9JzCmGVUdgjX3N/iU=
|
||||
github.com/google/uuid v1.6.0 h1:NIvaJDMOsjHA8n1jAhLSgzrAzy1Hgr+hNrb57e+94F0=
|
||||
github.com/google/uuid v1.6.0/go.mod h1:TIyPZe4MgqvfeYDBFedMoGGpEw/LqOeaOT+nhxU+yHo=
|
||||
github.com/hashicorp/errwrap v1.0.0/go.mod h1:YH+1FKiLXxHSkmPseP+kNlulaMuP3n2brvKWEqk/Jc4=
|
||||
github.com/hashicorp/errwrap v1.1.0 h1:OxrOeh75EUXMY8TBjag2fzXGZ40LB6IKw45YeGUDY2I=
|
||||
github.com/hashicorp/errwrap v1.1.0/go.mod h1:YH+1FKiLXxHSkmPseP+kNlulaMuP3n2brvKWEqk/Jc4=
|
||||
github.com/hashicorp/go-cleanhttp v0.5.2 h1:035FKYIWjmULyFRBKPs8TBQoi0x6d9G4xc9neXJWAZQ=
|
||||
github.com/hashicorp/go-cleanhttp v0.5.2/go.mod h1:kO/YDlP8L1346E6Sodw+PrpBSV4/SoxCXGY6BqNFT48=
|
||||
github.com/hashicorp/go-hclog v1.6.3 h1:Qr2kF+eVWjTiYmU7Y31tYlP1h0q/X3Nl3tPGdaB11/k=
|
||||
github.com/hashicorp/go-hclog v1.6.3/go.mod h1:W4Qnvbt70Wk/zYJryRzDRU/4r0kIg0PVHBcfoyhpF5M=
|
||||
github.com/hashicorp/go-multierror v1.0.0/go.mod h1:dHtQlpGsu+cZNNAkkCN/P3hoUDHhCYQXV3UM06sGGrk=
|
||||
github.com/hashicorp/go-multierror v1.1.1 h1:H5DkEtf6CXdFp0N0Em5UCwQpXMWke8IA0+lD48awMYo=
|
||||
github.com/hashicorp/go-multierror v1.1.1/go.mod h1:iw975J/qwKPdAO1clOe2L8331t/9/fmwbPZ6JB6eMoM=
|
||||
github.com/hashicorp/go-plugin v1.6.3 h1:xgHB+ZUSYeuJi96WtxEjzi23uh7YQpznjGh0U0UUrwg=
|
||||
github.com/hashicorp/go-plugin v1.6.3/go.mod h1:MRobyh+Wc/nYy1V4KAXUiYfzxoYhs7V1mlH1Z7iY2h0=
|
||||
github.com/hashicorp/go-retryablehttp v0.7.7 h1:C8hUCYzor8PIfXHa4UrZkU4VvK8o9ISHxT2Q8+VepXU=
|
||||
github.com/hashicorp/go-retryablehttp v0.7.7/go.mod h1:pkQpWZeYWskR+D1tR2O5OcBFOxfA7DoAO6xtkuQnHTk=
|
||||
github.com/hashicorp/go-rootcerts v1.0.2 h1:jzhAVGtqPKbwpyCPELlgNWhE1znq+qwJtW5Oi2viEzc=
|
||||
github.com/hashicorp/go-rootcerts v1.0.2/go.mod h1:pqUvnprVnM5bf7AOirdbb01K4ccR319Vf4pU3K5EGc8=
|
||||
github.com/hashicorp/go-secure-stdlib/parseutil v0.1.6 h1:om4Al8Oy7kCm/B86rLCLah4Dt5Aa0Fr5rYBG60OzwHQ=
|
||||
github.com/hashicorp/go-secure-stdlib/parseutil v0.1.6/go.mod h1:QmrqtbKuxxSWTN3ETMPuB+VtEiBJ/A9XhoYGv8E1uD8=
|
||||
github.com/hashicorp/go-secure-stdlib/strutil v0.1.1/go.mod h1:gKOamz3EwoIoJq7mlMIRBpVTAUn8qPCrEclOKKWhD3U=
|
||||
github.com/hashicorp/go-secure-stdlib/strutil v0.1.2 h1:kes8mmyCpxJsI7FTwtzRqEy9CdjCtrXrXGuOpxEA7Ts=
|
||||
github.com/hashicorp/go-secure-stdlib/strutil v0.1.2/go.mod h1:Gou2R9+il93BqX25LAKCLuM+y9U2T4hlwvT1yprcna4=
|
||||
github.com/hashicorp/go-sockaddr v1.0.2 h1:ztczhD1jLxIRjVejw8gFomI1BQZOe2WoVOu0SyteCQc=
|
||||
github.com/hashicorp/go-sockaddr v1.0.2/go.mod h1:rB4wwRAUzs07qva3c5SdrY/NEtAUjGlgmH/UkBUC97A=
|
||||
github.com/hashicorp/go-uuid v1.0.3 h1:2gKiV6YVmrJ1i2CKKa9obLvRieoRGviZFL26PcT/Co8=
|
||||
github.com/hashicorp/go-uuid v1.0.3/go.mod h1:6SBZvOh/SIDV7/2o3Jml5SYk/TvGqwFJ/bN7x4byOro=
|
||||
github.com/hashicorp/hcl v1.0.0 h1:0Anlzjpi4vEasTeNFn2mLJgTSwt0+6sfsiTG8qcWGx4=
|
||||
github.com/hashicorp/hcl v1.0.0/go.mod h1:E5yfLk+7swimpb2L/Alb/PJmXilQ/rhwaUYs4T20WEQ=
|
||||
github.com/hashicorp/terraform-plugin-framework v1.15.0 h1:LQ2rsOfmDLxcn5EeIwdXFtr03FVsNktbbBci8cOKdb4=
|
||||
github.com/hashicorp/terraform-plugin-framework v1.15.0/go.mod h1:hxrNI/GY32KPISpWqlCoTLM9JZsGH3CyYlir09bD/fI=
|
||||
github.com/hashicorp/terraform-plugin-go v0.27.0 h1:ujykws/fWIdsi6oTUT5Or4ukvEan4aN9lY+LOxVP8EE=
|
||||
github.com/hashicorp/terraform-plugin-go v0.27.0/go.mod h1:FDa2Bb3uumkTGSkTFpWSOwWJDwA7bf3vdP3ltLDTH6o=
|
||||
github.com/hashicorp/terraform-plugin-log v0.9.0 h1:i7hOA+vdAItN1/7UrfBqBwvYPQ9TFvymaRGZED3FCV0=
|
||||
github.com/hashicorp/terraform-plugin-log v0.9.0/go.mod h1:rKL8egZQ/eXSyDqzLUuwUYLVdlYeamldAHSxjUFADow=
|
||||
github.com/hashicorp/terraform-registry-address v0.2.5 h1:2GTftHqmUhVOeuu9CW3kwDkRe4pcBDq0uuK5VJngU1M=
|
||||
github.com/hashicorp/terraform-registry-address v0.2.5/go.mod h1:PpzXWINwB5kuVS5CA7m1+eO2f1jKb5ZDIxrOPfpnGkg=
|
||||
github.com/hashicorp/terraform-svchost v0.1.1 h1:EZZimZ1GxdqFRinZ1tpJwVxxt49xc/S52uzrw4x0jKQ=
|
||||
github.com/hashicorp/terraform-svchost v0.1.1/go.mod h1:mNsjQfZyf/Jhz35v6/0LWcv26+X7JPS+buii2c9/ctc=
|
||||
github.com/hashicorp/vault/api v1.15.0 h1:O24FYQCWwhwKnF7CuSqP30S51rTV7vz1iACXE/pj5DA=
|
||||
github.com/hashicorp/vault/api v1.15.0/go.mod h1:+5YTO09JGn0u+b6ySD/LLVf8WkJCPLAL2Vkmrn2+CM8=
|
||||
github.com/hashicorp/yamux v0.1.1 h1:yrQxtgseBDrq9Y652vSRDvsKCJKOUD+GzTS4Y0Y8pvE=
|
||||
github.com/hashicorp/yamux v0.1.1/go.mod h1:CtWFDAQgb7dxtzFs4tWbplKIe2jSi3+5vKbgIO0SLnQ=
|
||||
github.com/jhump/protoreflect v1.15.1 h1:HUMERORf3I3ZdX05WaQ6MIpd/NJ434hTp5YiKgfCL6c=
|
||||
github.com/jhump/protoreflect v1.15.1/go.mod h1:jD/2GMKKE6OqX8qTjhADU1e6DShO+gavG9e0Q693nKo=
|
||||
github.com/mattn/go-colorable v0.0.9/go.mod h1:9vuHe8Xs5qXnSaW/c/ABM9alt+Vo+STaOChaDxuIBZU=
|
||||
github.com/mattn/go-colorable v0.1.9/go.mod h1:u6P/XSegPjTcexA+o6vUJrdnUu04hMope9wVRipJSqc=
|
||||
github.com/mattn/go-colorable v0.1.12/go.mod h1:u5H1YNBxpqRaxsYJYSkiCWKzEfiAb1Gb520KVy5xxl4=
|
||||
github.com/mattn/go-colorable v0.1.13 h1:fFA4WZxdEF4tXPZVKMLwD8oUnCTTo08duU7wxecdEvA=
|
||||
github.com/mattn/go-colorable v0.1.13/go.mod h1:7S9/ev0klgBDR4GtXTXX8a3vIGJpMovkB8vQcUbaXHg=
|
||||
github.com/mattn/go-isatty v0.0.3/go.mod h1:M+lRXTBqGeGNdLjl/ufCoiOlB5xdOkqRJdNxMWT7Zi4=
|
||||
github.com/mattn/go-isatty v0.0.12/go.mod h1:cbi8OIDigv2wuxKPP5vlRcQ1OAZbq2CE4Kysco4FUpU=
|
||||
github.com/mattn/go-isatty v0.0.14/go.mod h1:7GGIvUiUoEMVVmxf/4nioHXj79iQHKdU27kJ6hsGG94=
|
||||
github.com/mattn/go-isatty v0.0.16/go.mod h1:kYGgaQfpe5nmfYZH+SKPsOc2e4SrIfOl2e/yFXSvRLM=
|
||||
github.com/mattn/go-isatty v0.0.20 h1:xfD0iDuEKnDkl03q4limB+vH+GxLEtL/jb4xVJSWWEY=
|
||||
github.com/mattn/go-isatty v0.0.20/go.mod h1:W+V8PltTTMOvKvAeJH7IuucS94S2C6jfK/D7dTCTo3Y=
|
||||
github.com/mitchellh/cli v1.0.0/go.mod h1:hNIlj7HEI86fIcpObd7a0FcrxTWetlwJDGcceTlRvqc=
|
||||
github.com/mitchellh/go-homedir v1.1.0 h1:lukF9ziXFxDFPkA1vsr5zpc1XuPDn/wFntq5mG+4E0Y=
|
||||
github.com/mitchellh/go-homedir v1.1.0/go.mod h1:SfyaCUpYCn1Vlf4IUYiD9fPX4A5wJrkLzIz1N1q0pr0=
|
||||
github.com/mitchellh/go-testing-interface v1.14.1 h1:jrgshOhYAUVNMAJiKbEu7EqAwgJJ2JqpQmpLJOu07cU=
|
||||
github.com/mitchellh/go-testing-interface v1.14.1/go.mod h1:gfgS7OtZj6MA4U1UrDRp04twqAjfvlZyCfX3sDjEym8=
|
||||
github.com/mitchellh/go-wordwrap v1.0.0/go.mod h1:ZXFpozHsX6DPmq2I0TCekCxypsnAUbP2oI0UX1GXzOo=
|
||||
github.com/mitchellh/mapstructure v1.4.1/go.mod h1:bFUtVrKA4DC2yAKiSyO/QUcy7e+RRV2QTWOzhPopBRo=
|
||||
github.com/mitchellh/mapstructure v1.5.0 h1:jeMsZIYE/09sWLaz43PL7Gy6RuMjD2eJVyuac5Z2hdY=
|
||||
github.com/mitchellh/mapstructure v1.5.0/go.mod h1:bFUtVrKA4DC2yAKiSyO/QUcy7e+RRV2QTWOzhPopBRo=
|
||||
github.com/oklog/run v1.0.0 h1:Ru7dDtJNOyC66gQ5dQmaCa0qIsAUFY3sFpK1Xk8igrw=
|
||||
github.com/oklog/run v1.0.0/go.mod h1:dlhp/R75TPv97u0XWUtDeV/lRKWPKSdTuV0TZvrmrQA=
|
||||
github.com/pmezard/go-difflib v1.0.0 h1:4DBwDE0NGyQoBHbLQYPwSUPoCMWR5BEzIk/f1lZbAQM=
|
||||
github.com/pmezard/go-difflib v1.0.0/go.mod h1:iKH77koFhYxTK1pcRnkKkqfTogsbg7gZNVY4sRDYZ/4=
|
||||
github.com/posener/complete v1.1.1/go.mod h1:em0nMJCgc9GFtwrmVmEMR/ZL6WyhyjMBndrE9hABlRI=
|
||||
github.com/ryanuber/columnize v2.1.0+incompatible/go.mod h1:sm1tb6uqfes/u+d4ooFouqFdy9/2g9QGwK3SQygK0Ts=
|
||||
github.com/ryanuber/go-glob v1.0.0 h1:iQh3xXAumdQ+4Ufa5b25cRpC5TYKlno6hsv6Cb3pkBk=
|
||||
github.com/ryanuber/go-glob v1.0.0/go.mod h1:807d1WSdnB0XRJzKNil9Om6lcp/3a0v4qIHxIXzX/Yc=
|
||||
github.com/stretchr/objx v0.1.0/go.mod h1:HFkY916IF+rwdDfMAkV7OtwuqBVzrE8GR6GFx+wExME=
|
||||
github.com/stretchr/testify v1.7.0/go.mod h1:6Fq8oRcR53rry900zMqJjRRixrwX3KX962/h/Wwjteg=
|
||||
github.com/stretchr/testify v1.7.2/go.mod h1:R6va5+xMeoiuVRoj+gSkQ7d3FALtqAAGI1FQKckRals=
|
||||
github.com/stretchr/testify v1.9.0 h1:HtqpIVDClZ4nwg75+f6Lvsy/wHu+3BoSGCbBAcpTsTg=
|
||||
github.com/stretchr/testify v1.9.0/go.mod h1:r2ic/lqez/lEtzL7wO/rwa5dbSLXVDPFyf8C91i36aY=
|
||||
github.com/vmihailenco/msgpack/v5 v5.4.1 h1:cQriyiUvjTwOHg8QZaPihLWeRAAVoCpE00IUPn0Bjt8=
|
||||
github.com/vmihailenco/msgpack/v5 v5.4.1/go.mod h1:GaZTsDaehaPpQVyxrf5mtQlH+pc21PIudVV/E3rRQok=
|
||||
github.com/vmihailenco/tagparser/v2 v2.0.0 h1:y09buUbR+b5aycVFQs/g70pqKVZNBmxwAhO7/IwNM9g=
|
||||
github.com/vmihailenco/tagparser/v2 v2.0.0/go.mod h1:Wri+At7QHww0WTrCBeu4J6bNtoV6mEfg5OIWRZA9qds=
|
||||
go.opentelemetry.io/auto/sdk v1.1.0 h1:cH53jehLUN6UFLY71z+NDOiNJqDdPRaXzTel0sJySYA=
|
||||
go.opentelemetry.io/auto/sdk v1.1.0/go.mod h1:3wSPjt5PWp2RhlCcmmOial7AvC4DQqZb7a7wCow3W8A=
|
||||
go.opentelemetry.io/otel v1.34.0 h1:zRLXxLCgL1WyKsPVrgbSdMN4c0FMkDAskSTQP+0hdUY=
|
||||
go.opentelemetry.io/otel v1.34.0/go.mod h1:OWFPOQ+h4G8xpyjgqo4SxJYdDQ/qmRH+wivy7zzx9oI=
|
||||
go.opentelemetry.io/otel/metric v1.34.0 h1:+eTR3U0MyfWjRDhmFMxe2SsW64QrZ84AOhvqS7Y+PoQ=
|
||||
go.opentelemetry.io/otel/metric v1.34.0/go.mod h1:CEDrp0fy2D0MvkXE+dPV7cMi8tWZwX3dmaIhwPOaqHE=
|
||||
go.opentelemetry.io/otel/sdk v1.34.0 h1:95zS4k/2GOy069d321O8jWgYsW3MzVV+KuSPKp7Wr1A=
|
||||
go.opentelemetry.io/otel/sdk v1.34.0/go.mod h1:0e/pNiaMAqaykJGKbi+tSjWfNNHMTxoC9qANsCzbyxU=
|
||||
go.opentelemetry.io/otel/sdk/metric v1.34.0 h1:5CeK9ujjbFVL5c1PhLuStg1wxA7vQv7ce1EK0Gyvahk=
|
||||
go.opentelemetry.io/otel/sdk/metric v1.34.0/go.mod h1:jQ/r8Ze28zRKoNRdkjCZxfs6YvBTG1+YIqyFVFYec5w=
|
||||
go.opentelemetry.io/otel/trace v1.34.0 h1:+ouXS2V8Rd4hp4580a8q23bg0azF2nI8cqLYnC8mh/k=
|
||||
go.opentelemetry.io/otel/trace v1.34.0/go.mod h1:Svm7lSjQD7kG7KJ/MUHPVXSDGz2OX4h0M2jHBhmSfRE=
|
||||
golang.org/x/crypto v0.37.0 h1:kJNSjF/Xp7kU0iB2Z+9viTPMW4EqqsrywMXLJOOsXSE=
|
||||
golang.org/x/crypto v0.37.0/go.mod h1:vg+k43peMZ0pUMhYmVAWysMK35e6ioLh3wB8ZCAfbVc=
|
||||
golang.org/x/net v0.39.0 h1:ZCu7HMWDxpXpaiKdhzIfaltL9Lp31x/3fCP11bc6/fY=
|
||||
golang.org/x/net v0.39.0/go.mod h1:X7NRbYVEA+ewNkCNyJ513WmMdQ3BineSwVtN2zD/d+E=
|
||||
golang.org/x/sys v0.0.0-20180823144017-11551d06cbcc/go.mod h1:STP8DvDyc/dI5b8T5hshtkjS+E42TnysNCUPdjciGhY=
|
||||
golang.org/x/sys v0.0.0-20200116001909-b77594299b42/go.mod h1:h1NjWce9XRLGQEsW7wpKNCjG9DtNlClVuFLEZdDNbEs=
|
||||
golang.org/x/sys v0.0.0-20200223170610-d5e6a3e2c0ae/go.mod h1:h1NjWce9XRLGQEsW7wpKNCjG9DtNlClVuFLEZdDNbEs=
|
||||
golang.org/x/sys v0.0.0-20210630005230-0f9fa26af87c/go.mod h1:oPkhp1MJrh7nUepCBck5+mAzfO9JrbApNNgaTdGDITg=
|
||||
golang.org/x/sys v0.0.0-20210927094055-39ccf1dd6fa6/go.mod h1:oPkhp1MJrh7nUepCBck5+mAzfO9JrbApNNgaTdGDITg=
|
||||
golang.org/x/sys v0.0.0-20220503163025-988cb79eb6c6/go.mod h1:oPkhp1MJrh7nUepCBck5+mAzfO9JrbApNNgaTdGDITg=
|
||||
golang.org/x/sys v0.0.0-20220811171246-fbc7d0a398ab/go.mod h1:oPkhp1MJrh7nUepCBck5+mAzfO9JrbApNNgaTdGDITg=
|
||||
golang.org/x/sys v0.6.0/go.mod h1:oPkhp1MJrh7nUepCBck5+mAzfO9JrbApNNgaTdGDITg=
|
||||
golang.org/x/sys v0.32.0 h1:s77OFDvIQeibCmezSnk/q6iAfkdiQaJi4VzroCFrN20=
|
||||
golang.org/x/sys v0.32.0/go.mod h1:BJP2sWEmIv4KK5OTEluFJCKSidICx8ciO85XgH3Ak8k=
|
||||
golang.org/x/text v0.24.0 h1:dd5Bzh4yt5KYA8f9CJHCP4FB4D51c2c6JvN37xJJkJ0=
|
||||
golang.org/x/text v0.24.0/go.mod h1:L8rBsPeo2pSS+xqN0d5u2ikmjtmoJbDBT1b7nHvFCdU=
|
||||
golang.org/x/time v0.0.0-20200416051211-89c76fbcd5d1 h1:NusfzzA6yGQ+ua51ck7E3omNUX/JuqbFSaRGqU8CcLI=
|
||||
golang.org/x/time v0.0.0-20200416051211-89c76fbcd5d1/go.mod h1:tRJNPiyCQ0inRvYxbN9jk5I+vvW/OXSQhTDSoE431IQ=
|
||||
google.golang.org/genproto/googleapis/rpc v0.0.0-20250218202821-56aae31c358a h1:51aaUVRocpvUOSQKM6Q7VuoaktNIaMCLuhZB6DKksq4=
|
||||
google.golang.org/genproto/googleapis/rpc v0.0.0-20250218202821-56aae31c358a/go.mod h1:uRxBH1mhmO8PGhU89cMcHaXKZqO+OfakD8QQO0oYwlQ=
|
||||
google.golang.org/grpc v1.72.1 h1:HR03wO6eyZ7lknl75XlxABNVLLFc2PAb6mHlYh756mA=
|
||||
google.golang.org/grpc v1.72.1/go.mod h1:wH5Aktxcg25y1I3w7H69nHfXdOG3UiadoBtjh3izSDM=
|
||||
google.golang.org/protobuf v1.36.6 h1:z1NpPI8ku2WgiWnf+t9wTPsn6eP1L7ksHUlkfLvd9xY=
|
||||
google.golang.org/protobuf v1.36.6/go.mod h1:jduwjTPXsFjZGTmRluh+L6NjiWu7pchiJ2/5YcXBHnY=
|
||||
gopkg.in/check.v1 v0.0.0-20161208181325-20d25e280405/go.mod h1:Co6ibVJAznAaIkqp8huTwlJQCZ016jof/cbN4VW5Yz0=
|
||||
gopkg.in/yaml.v3 v3.0.0-20200313102051-9f266ea9e77c/go.mod h1:K4uyk7z7BCEPqu6E+C64Yfv1cQ7kz7rIZviUmN+EgEM=
|
||||
gopkg.in/yaml.v3 v3.0.1 h1:fxVm/GzAzEWqLHuvctI91KS9hhNmmWOoWu0XTYJS7CA=
|
||||
gopkg.in/yaml.v3 v3.0.1/go.mod h1:K4uyk7z7BCEPqu6E+C64Yfv1cQ7kz7rIZviUmN+EgEM=
|
||||
@@ -0,0 +1,170 @@
|
||||
package provider
|
||||
|
||||
import (
|
||||
"context"
|
||||
"errors"
|
||||
"fmt"
|
||||
"strings"
|
||||
|
||||
vault "github.com/hashicorp/vault/api"
|
||||
)
|
||||
|
||||
// vaultClient wraps the Vault/OpenBao API client with the operations this
|
||||
// provider needs to manage the gpg secrets engine and its keys.
|
||||
type vaultClient struct {
|
||||
api *vault.Client
|
||||
}
|
||||
|
||||
func newVaultClient(address, token string) (*vaultClient, error) {
|
||||
cfg := vault.DefaultConfig()
|
||||
if cfg.Error != nil {
|
||||
return nil, cfg.Error
|
||||
}
|
||||
if address != "" {
|
||||
cfg.Address = address
|
||||
}
|
||||
c, err := vault.NewClient(cfg)
|
||||
if err != nil {
|
||||
return nil, err
|
||||
}
|
||||
if token != "" {
|
||||
c.SetToken(token)
|
||||
}
|
||||
return &vaultClient{api: c}, nil
|
||||
}
|
||||
|
||||
// --- plugin catalog ---
|
||||
|
||||
// registerPlugin registers (or updates) a secret plugin in the catalog.
|
||||
func (c *vaultClient) registerPlugin(ctx context.Context, name, command, sha256 string) error {
|
||||
return c.api.Sys().RegisterPluginWithContext(ctx, &vault.RegisterPluginInput{
|
||||
Name: name,
|
||||
Type: vault.PluginTypeSecrets,
|
||||
Command: command,
|
||||
SHA256: sha256,
|
||||
})
|
||||
}
|
||||
|
||||
// deregisterPlugin removes a secret plugin from the catalog.
|
||||
func (c *vaultClient) deregisterPlugin(ctx context.Context, name string) error {
|
||||
return c.api.Sys().DeregisterPluginWithContext(ctx, &vault.DeregisterPluginInput{
|
||||
Name: name,
|
||||
Type: vault.PluginTypeSecrets,
|
||||
})
|
||||
}
|
||||
|
||||
// pluginInfo returns the catalog entry for a secret plugin, or nil if absent.
|
||||
func (c *vaultClient) pluginInfo(ctx context.Context, name string) (*vault.GetPluginResponse, error) {
|
||||
info, err := c.api.Sys().GetPluginWithContext(ctx, &vault.GetPluginInput{
|
||||
Name: name,
|
||||
Type: vault.PluginTypeSecrets,
|
||||
})
|
||||
if err != nil {
|
||||
if isNotFound(err) {
|
||||
return nil, nil
|
||||
}
|
||||
return nil, err
|
||||
}
|
||||
return info, nil
|
||||
}
|
||||
|
||||
// --- mounts ---
|
||||
|
||||
func (c *vaultClient) enableMount(ctx context.Context, path, pluginType, description string) error {
|
||||
return c.api.Sys().MountWithContext(ctx, path, &vault.MountInput{
|
||||
Type: pluginType,
|
||||
Description: description,
|
||||
})
|
||||
}
|
||||
|
||||
func (c *vaultClient) tuneMount(ctx context.Context, path, description string) error {
|
||||
return c.api.Sys().TuneMountWithContext(ctx, path, vault.MountConfigInput{
|
||||
Description: &description,
|
||||
})
|
||||
}
|
||||
|
||||
// mountInfo returns the mount at path, or nil if it does not exist.
|
||||
func (c *vaultClient) mountInfo(ctx context.Context, path string) (*vault.MountOutput, error) {
|
||||
mounts, err := c.api.Sys().ListMountsWithContext(ctx)
|
||||
if err != nil {
|
||||
return nil, err
|
||||
}
|
||||
key := strings.TrimRight(path, "/") + "/"
|
||||
if m, ok := mounts[key]; ok {
|
||||
return m, nil
|
||||
}
|
||||
return nil, nil
|
||||
}
|
||||
|
||||
func (c *vaultClient) disableMount(ctx context.Context, path string) error {
|
||||
return c.api.Sys().UnmountWithContext(ctx, path)
|
||||
}
|
||||
|
||||
// --- keys ---
|
||||
|
||||
func (c *vaultClient) writeKey(ctx context.Context, backend, name string, data map[string]interface{}) (map[string]interface{}, error) {
|
||||
secret, err := c.api.Logical().WriteWithContext(ctx, keyPath(backend, name), data)
|
||||
if err != nil {
|
||||
return nil, err
|
||||
}
|
||||
if secret == nil {
|
||||
return nil, nil
|
||||
}
|
||||
return secret.Data, nil
|
||||
}
|
||||
|
||||
// readKey reads a key's metadata, returning nil if it does not exist.
|
||||
func (c *vaultClient) readKey(ctx context.Context, backend, name string) (map[string]interface{}, error) {
|
||||
secret, err := c.api.Logical().ReadWithContext(ctx, keyPath(backend, name))
|
||||
if err != nil {
|
||||
return nil, err
|
||||
}
|
||||
if secret == nil {
|
||||
return nil, nil
|
||||
}
|
||||
return secret.Data, nil
|
||||
}
|
||||
|
||||
func (c *vaultClient) writeKeyConfig(ctx context.Context, backend, name string, data map[string]interface{}) error {
|
||||
_, err := c.api.Logical().WriteWithContext(ctx, keyPath(backend, name)+"/config", data)
|
||||
return err
|
||||
}
|
||||
|
||||
func (c *vaultClient) deleteKey(ctx context.Context, backend, name string) error {
|
||||
_, err := c.api.Logical().DeleteWithContext(ctx, keyPath(backend, name))
|
||||
return err
|
||||
}
|
||||
|
||||
func keyPath(backend, name string) string {
|
||||
return fmt.Sprintf("%s/keys/%s", strings.TrimRight(backend, "/"), name)
|
||||
}
|
||||
|
||||
// isMountAlreadyExists reports whether the error is Vault's "path is already in
|
||||
// use" response.
|
||||
func isMountAlreadyExists(err error) bool {
|
||||
return responseContains(err, "path is already in use")
|
||||
}
|
||||
|
||||
// isNotFound reports a 404-style response from Vault.
|
||||
func isNotFound(err error) bool {
|
||||
var respErr *vault.ResponseError
|
||||
if errors.As(err, &respErr) {
|
||||
return respErr.StatusCode == 404
|
||||
}
|
||||
return false
|
||||
}
|
||||
|
||||
func responseContains(err error, substr string) bool {
|
||||
if err == nil {
|
||||
return false
|
||||
}
|
||||
var respErr *vault.ResponseError
|
||||
if errors.As(err, &respErr) {
|
||||
for _, e := range respErr.Errors {
|
||||
if strings.Contains(e, substr) {
|
||||
return true
|
||||
}
|
||||
}
|
||||
}
|
||||
return false
|
||||
}
|
||||
@@ -0,0 +1,36 @@
|
||||
package provider
|
||||
|
||||
import "encoding/json"
|
||||
|
||||
// toInt64 coerces the numeric shapes Vault returns (json.Number, float64, int)
|
||||
// into an int64.
|
||||
func toInt64(v interface{}) (int64, bool) {
|
||||
switch n := v.(type) {
|
||||
case json.Number:
|
||||
if i, err := n.Int64(); err == nil {
|
||||
return i, true
|
||||
}
|
||||
if f, err := n.Float64(); err == nil {
|
||||
return int64(f), true
|
||||
}
|
||||
return 0, false
|
||||
case float64:
|
||||
return int64(n), true
|
||||
case int64:
|
||||
return n, true
|
||||
case int:
|
||||
return int64(n), true
|
||||
default:
|
||||
return 0, false
|
||||
}
|
||||
}
|
||||
|
||||
func toBool(v interface{}) (bool, bool) {
|
||||
b, ok := v.(bool)
|
||||
return b, ok
|
||||
}
|
||||
|
||||
func toString(v interface{}) (string, bool) {
|
||||
s, ok := v.(string)
|
||||
return s, ok
|
||||
}
|
||||
@@ -0,0 +1,125 @@
|
||||
package provider
|
||||
|
||||
import (
|
||||
"context"
|
||||
"fmt"
|
||||
"strings"
|
||||
|
||||
"github.com/hashicorp/terraform-plugin-framework/datasource"
|
||||
"github.com/hashicorp/terraform-plugin-framework/datasource/schema"
|
||||
"github.com/hashicorp/terraform-plugin-framework/types"
|
||||
)
|
||||
|
||||
var _ datasource.DataSource = &keyDataSource{}
|
||||
|
||||
type keyDataSource struct {
|
||||
client *vaultClient
|
||||
}
|
||||
|
||||
type keyDataSourceModel struct {
|
||||
Backend types.String `tfsdk:"backend"`
|
||||
Name types.String `tfsdk:"name"`
|
||||
Algorithm types.String `tfsdk:"algorithm"`
|
||||
Identity types.String `tfsdk:"identity"`
|
||||
Exportable types.Bool `tfsdk:"exportable"`
|
||||
DeletionAllowed types.Bool `tfsdk:"deletion_allowed"`
|
||||
MinDecryptionVersion types.Int64 `tfsdk:"min_decryption_version"`
|
||||
LatestVersion types.Int64 `tfsdk:"latest_version"`
|
||||
Fingerprint types.String `tfsdk:"fingerprint"`
|
||||
KeyID types.String `tfsdk:"key_id"`
|
||||
PublicKey types.String `tfsdk:"public_key"`
|
||||
}
|
||||
|
||||
func NewKeyDataSource() datasource.DataSource {
|
||||
return &keyDataSource{}
|
||||
}
|
||||
|
||||
func (d *keyDataSource) Metadata(_ context.Context, req datasource.MetadataRequest, resp *datasource.MetadataResponse) {
|
||||
resp.TypeName = req.ProviderTypeName + "_key"
|
||||
}
|
||||
|
||||
func (d *keyDataSource) Schema(_ context.Context, _ datasource.SchemaRequest, resp *datasource.SchemaResponse) {
|
||||
resp.Schema = schema.Schema{
|
||||
Description: "Reads an OpenPGP key's metadata and armored public key from a gpg secrets engine mount.",
|
||||
Attributes: map[string]schema.Attribute{
|
||||
"backend": schema.StringAttribute{
|
||||
Description: "Mount path of the gpg secrets engine.",
|
||||
Required: true,
|
||||
},
|
||||
"name": schema.StringAttribute{
|
||||
Description: "Name of the key.",
|
||||
Required: true,
|
||||
},
|
||||
"algorithm": schema.StringAttribute{Description: "Key algorithm.", Computed: true},
|
||||
"identity": schema.StringAttribute{Description: "OpenPGP User ID.", Computed: true},
|
||||
"exportable": schema.BoolAttribute{Description: "Whether the private key is exportable.", Computed: true},
|
||||
"deletion_allowed": schema.BoolAttribute{Description: "Whether the key may be deleted.", Computed: true},
|
||||
"min_decryption_version": schema.Int64Attribute{Description: "Minimum usable version for decryption/verification.", Computed: true},
|
||||
"latest_version": schema.Int64Attribute{Description: "Current (highest) key version.", Computed: true},
|
||||
"fingerprint": schema.StringAttribute{Description: "OpenPGP fingerprint of the latest version.", Computed: true},
|
||||
"key_id": schema.StringAttribute{Description: "OpenPGP key ID of the latest version.", Computed: true},
|
||||
"public_key": schema.StringAttribute{Description: "Armored public key of the latest version.", Computed: true},
|
||||
},
|
||||
}
|
||||
}
|
||||
|
||||
func (d *keyDataSource) Configure(_ context.Context, req datasource.ConfigureRequest, resp *datasource.ConfigureResponse) {
|
||||
if req.ProviderData == nil {
|
||||
return
|
||||
}
|
||||
client, ok := req.ProviderData.(*vaultClient)
|
||||
if !ok {
|
||||
resp.Diagnostics.AddError("unexpected provider data type", fmt.Sprintf("got %T", req.ProviderData))
|
||||
return
|
||||
}
|
||||
d.client = client
|
||||
}
|
||||
|
||||
func (d *keyDataSource) Read(ctx context.Context, req datasource.ReadRequest, resp *datasource.ReadResponse) {
|
||||
var config keyDataSourceModel
|
||||
resp.Diagnostics.Append(req.Config.Get(ctx, &config)...)
|
||||
if resp.Diagnostics.HasError() {
|
||||
return
|
||||
}
|
||||
|
||||
backend := strings.Trim(config.Backend.ValueString(), "/")
|
||||
name := config.Name.ValueString()
|
||||
|
||||
data, err := d.client.readKey(ctx, backend, name)
|
||||
if err != nil {
|
||||
resp.Diagnostics.AddError("failed to read gpg key", err.Error())
|
||||
return
|
||||
}
|
||||
if data == nil {
|
||||
resp.Diagnostics.AddError("gpg key not found", fmt.Sprintf("no key %q in backend %q", name, backend))
|
||||
return
|
||||
}
|
||||
|
||||
if s, ok := toString(data["algorithm"]); ok {
|
||||
config.Algorithm = types.StringValue(s)
|
||||
}
|
||||
if s, ok := toString(data["identity"]); ok {
|
||||
config.Identity = types.StringValue(s)
|
||||
}
|
||||
if b, ok := toBool(data["exportable"]); ok {
|
||||
config.Exportable = types.BoolValue(b)
|
||||
}
|
||||
if b, ok := toBool(data["deletion_allowed"]); ok {
|
||||
config.DeletionAllowed = types.BoolValue(b)
|
||||
}
|
||||
if n, ok := toInt64(data["min_decryption_version"]); ok {
|
||||
config.MinDecryptionVersion = types.Int64Value(n)
|
||||
}
|
||||
if n, ok := toInt64(data["latest_version"]); ok {
|
||||
config.LatestVersion = types.Int64Value(n)
|
||||
}
|
||||
if s, ok := toString(data["fingerprint"]); ok {
|
||||
config.Fingerprint = types.StringValue(s)
|
||||
}
|
||||
if s, ok := toString(data["public_key"]); ok {
|
||||
config.PublicKey = types.StringValue(s)
|
||||
}
|
||||
config.KeyID = types.StringValue(keyIDForLatest(data))
|
||||
|
||||
resp.Diagnostics.Append(resp.State.Set(ctx, config)...)
|
||||
}
|
||||
@@ -0,0 +1,102 @@
|
||||
package provider
|
||||
|
||||
import (
|
||||
"context"
|
||||
"os"
|
||||
|
||||
"github.com/hashicorp/terraform-plugin-framework/datasource"
|
||||
"github.com/hashicorp/terraform-plugin-framework/provider"
|
||||
"github.com/hashicorp/terraform-plugin-framework/provider/schema"
|
||||
"github.com/hashicorp/terraform-plugin-framework/resource"
|
||||
"github.com/hashicorp/terraform-plugin-framework/types"
|
||||
)
|
||||
|
||||
var _ provider.Provider = &gpgProvider{}
|
||||
|
||||
type gpgProvider struct {
|
||||
version string
|
||||
}
|
||||
|
||||
type gpgProviderModel struct {
|
||||
Address types.String `tfsdk:"address"`
|
||||
Token types.String `tfsdk:"token"`
|
||||
}
|
||||
|
||||
func New(version string) func() provider.Provider {
|
||||
return func() provider.Provider {
|
||||
return &gpgProvider{version: version}
|
||||
}
|
||||
}
|
||||
|
||||
func (p *gpgProvider) Metadata(_ context.Context, _ provider.MetadataRequest, resp *provider.MetadataResponse) {
|
||||
// The provider's source address is git.unkin.net/unkin/gpgvaultsecret, but
|
||||
// its resources are prefixed "gpg_" (declare it in required_providers under
|
||||
// the local name "gpg"), mirroring how google-beta ships google_*.
|
||||
resp.TypeName = "gpg"
|
||||
resp.Version = p.version
|
||||
}
|
||||
|
||||
func (p *gpgProvider) Schema(_ context.Context, _ provider.SchemaRequest, resp *provider.SchemaResponse) {
|
||||
resp.Schema = schema.Schema{
|
||||
Description: "Manage the vault-plugin-secrets-gpg engine — mounts and OpenPGP keys — on HashiCorp Vault or OpenBao.",
|
||||
Attributes: map[string]schema.Attribute{
|
||||
"address": schema.StringAttribute{
|
||||
Description: "Address of the Vault/OpenBao server. Falls back to the VAULT_ADDR environment variable.",
|
||||
Optional: true,
|
||||
},
|
||||
"token": schema.StringAttribute{
|
||||
Description: "Token used to authenticate to Vault/OpenBao. Falls back to the VAULT_TOKEN environment variable.",
|
||||
Optional: true,
|
||||
Sensitive: true,
|
||||
},
|
||||
},
|
||||
}
|
||||
}
|
||||
|
||||
func (p *gpgProvider) Configure(ctx context.Context, req provider.ConfigureRequest, resp *provider.ConfigureResponse) {
|
||||
var config gpgProviderModel
|
||||
resp.Diagnostics.Append(req.Config.Get(ctx, &config)...)
|
||||
if resp.Diagnostics.HasError() {
|
||||
return
|
||||
}
|
||||
|
||||
address := os.Getenv("VAULT_ADDR")
|
||||
if !config.Address.IsNull() && config.Address.ValueString() != "" {
|
||||
address = config.Address.ValueString()
|
||||
}
|
||||
|
||||
token := os.Getenv("VAULT_TOKEN")
|
||||
if !config.Token.IsNull() && config.Token.ValueString() != "" {
|
||||
token = config.Token.ValueString()
|
||||
}
|
||||
|
||||
if address == "" {
|
||||
resp.Diagnostics.AddError(
|
||||
"missing Vault address",
|
||||
"Set the provider \"address\" attribute or the VAULT_ADDR environment variable.",
|
||||
)
|
||||
return
|
||||
}
|
||||
|
||||
client, err := newVaultClient(address, token)
|
||||
if err != nil {
|
||||
resp.Diagnostics.AddError("failed to create Vault client", err.Error())
|
||||
return
|
||||
}
|
||||
|
||||
resp.DataSourceData = client
|
||||
resp.ResourceData = client
|
||||
}
|
||||
|
||||
func (p *gpgProvider) Resources(_ context.Context) []func() resource.Resource {
|
||||
return []func() resource.Resource{
|
||||
NewSecretBackendResource,
|
||||
NewKeyResource,
|
||||
}
|
||||
}
|
||||
|
||||
func (p *gpgProvider) DataSources(_ context.Context) []func() datasource.DataSource {
|
||||
return []func() datasource.DataSource{
|
||||
NewKeyDataSource,
|
||||
}
|
||||
}
|
||||
@@ -0,0 +1,108 @@
|
||||
package provider
|
||||
|
||||
import (
|
||||
"encoding/json"
|
||||
"testing"
|
||||
|
||||
"github.com/hashicorp/terraform-plugin-framework/types"
|
||||
)
|
||||
|
||||
func TestToInt64(t *testing.T) {
|
||||
cases := []struct {
|
||||
in interface{}
|
||||
want int64
|
||||
ok bool
|
||||
}{
|
||||
{json.Number("3"), 3, true},
|
||||
{json.Number("3.0"), 3, true},
|
||||
{float64(5), 5, true},
|
||||
{int(7), 7, true},
|
||||
{int64(9), 9, true},
|
||||
{"nope", 0, false},
|
||||
{nil, 0, false},
|
||||
}
|
||||
for _, c := range cases {
|
||||
got, ok := toInt64(c.in)
|
||||
if ok != c.ok || (ok && got != c.want) {
|
||||
t.Errorf("toInt64(%v) = (%d,%v), want (%d,%v)", c.in, got, ok, c.want, c.ok)
|
||||
}
|
||||
}
|
||||
}
|
||||
|
||||
func TestResolveCommand(t *testing.T) {
|
||||
// explicit command wins
|
||||
m := secretBackendModel{
|
||||
Plugin: types.StringValue("vault-plugin-secrets-gpg"),
|
||||
Command: types.StringValue("custom-binary"),
|
||||
}
|
||||
if got := resolveCommand(m); got != "custom-binary" {
|
||||
t.Errorf("resolveCommand explicit = %q", got)
|
||||
}
|
||||
// falls back to plugin name when command is null
|
||||
m = secretBackendModel{
|
||||
Plugin: types.StringValue("vault-plugin-secrets-gpg"),
|
||||
Command: types.StringNull(),
|
||||
}
|
||||
if got := resolveCommand(m); got != "vault-plugin-secrets-gpg" {
|
||||
t.Errorf("resolveCommand fallback = %q", got)
|
||||
}
|
||||
}
|
||||
|
||||
func TestManagesPlugin(t *testing.T) {
|
||||
if managesPlugin(secretBackendModel{SHA256: types.StringNull()}) {
|
||||
t.Error("null sha256 should not manage the plugin")
|
||||
}
|
||||
if managesPlugin(secretBackendModel{SHA256: types.StringValue("")}) {
|
||||
t.Error("empty sha256 should not manage the plugin")
|
||||
}
|
||||
if !managesPlugin(secretBackendModel{SHA256: types.StringValue("abc123")}) {
|
||||
t.Error("set sha256 should manage the plugin")
|
||||
}
|
||||
}
|
||||
|
||||
func TestKeyIDForLatest(t *testing.T) {
|
||||
data := map[string]interface{}{
|
||||
"latest_version": json.Number("2"),
|
||||
"keys": map[string]interface{}{
|
||||
"1": map[string]interface{}{"key_id": "AAAA1111"},
|
||||
"2": map[string]interface{}{"key_id": "BBBB2222"},
|
||||
},
|
||||
}
|
||||
if got := keyIDForLatest(data); got != "BBBB2222" {
|
||||
t.Errorf("keyIDForLatest = %q, want BBBB2222", got)
|
||||
}
|
||||
|
||||
// missing data yields empty string, not a panic
|
||||
if got := keyIDForLatest(map[string]interface{}{}); got != "" {
|
||||
t.Errorf("keyIDForLatest(empty) = %q, want \"\"", got)
|
||||
}
|
||||
}
|
||||
|
||||
func TestApplyKeyData(t *testing.T) {
|
||||
m := &keyModel{}
|
||||
applyKeyData(m, map[string]interface{}{
|
||||
"algorithm": "ed25519",
|
||||
"identity": "Me <me@x>",
|
||||
"exportable": true,
|
||||
"deletion_allowed": false,
|
||||
"min_decryption_version": json.Number("1"),
|
||||
"latest_version": json.Number("1"),
|
||||
"fingerprint": "DEADBEEF",
|
||||
"public_key": "-----BEGIN PGP PUBLIC KEY BLOCK-----",
|
||||
"keys": map[string]interface{}{
|
||||
"1": map[string]interface{}{"key_id": "CAFED00D"},
|
||||
},
|
||||
})
|
||||
if m.Algorithm.ValueString() != "ed25519" {
|
||||
t.Errorf("algorithm = %q", m.Algorithm.ValueString())
|
||||
}
|
||||
if !m.Exportable.ValueBool() {
|
||||
t.Error("exportable should be true")
|
||||
}
|
||||
if m.Fingerprint.ValueString() != "DEADBEEF" {
|
||||
t.Errorf("fingerprint = %q", m.Fingerprint.ValueString())
|
||||
}
|
||||
if m.KeyID.ValueString() != "CAFED00D" {
|
||||
t.Errorf("key_id = %q", m.KeyID.ValueString())
|
||||
}
|
||||
}
|
||||
@@ -0,0 +1,322 @@
|
||||
package provider
|
||||
|
||||
import (
|
||||
"context"
|
||||
"fmt"
|
||||
"strings"
|
||||
|
||||
"github.com/hashicorp/terraform-plugin-framework/diag"
|
||||
"github.com/hashicorp/terraform-plugin-framework/path"
|
||||
"github.com/hashicorp/terraform-plugin-framework/resource"
|
||||
"github.com/hashicorp/terraform-plugin-framework/resource/schema"
|
||||
"github.com/hashicorp/terraform-plugin-framework/resource/schema/booldefault"
|
||||
"github.com/hashicorp/terraform-plugin-framework/resource/schema/planmodifier"
|
||||
"github.com/hashicorp/terraform-plugin-framework/resource/schema/stringdefault"
|
||||
"github.com/hashicorp/terraform-plugin-framework/resource/schema/stringplanmodifier"
|
||||
"github.com/hashicorp/terraform-plugin-framework/types"
|
||||
)
|
||||
|
||||
var (
|
||||
_ resource.Resource = &keyResource{}
|
||||
_ resource.ResourceWithImportState = &keyResource{}
|
||||
)
|
||||
|
||||
type keyResource struct {
|
||||
client *vaultClient
|
||||
}
|
||||
|
||||
type keyModel struct {
|
||||
Backend types.String `tfsdk:"backend"`
|
||||
Name types.String `tfsdk:"name"`
|
||||
Algorithm types.String `tfsdk:"algorithm"`
|
||||
Identity types.String `tfsdk:"identity"`
|
||||
Exportable types.Bool `tfsdk:"exportable"`
|
||||
DeletionAllowed types.Bool `tfsdk:"deletion_allowed"`
|
||||
MinDecryptionVersion types.Int64 `tfsdk:"min_decryption_version"`
|
||||
|
||||
LatestVersion types.Int64 `tfsdk:"latest_version"`
|
||||
Fingerprint types.String `tfsdk:"fingerprint"`
|
||||
KeyID types.String `tfsdk:"key_id"`
|
||||
PublicKey types.String `tfsdk:"public_key"`
|
||||
}
|
||||
|
||||
func NewKeyResource() resource.Resource {
|
||||
return &keyResource{}
|
||||
}
|
||||
|
||||
func (r *keyResource) Metadata(_ context.Context, req resource.MetadataRequest, resp *resource.MetadataResponse) {
|
||||
resp.TypeName = req.ProviderTypeName + "_key"
|
||||
}
|
||||
|
||||
func (r *keyResource) Schema(_ context.Context, _ resource.SchemaRequest, resp *resource.SchemaResponse) {
|
||||
requiresReplace := []planmodifier.String{stringplanmodifier.RequiresReplace()}
|
||||
resp.Schema = schema.Schema{
|
||||
Description: "Manages an OpenPGP key in a gpg secrets engine mount.",
|
||||
Attributes: map[string]schema.Attribute{
|
||||
"backend": schema.StringAttribute{
|
||||
Description: "Mount path of the gpg secrets engine (e.g. \"gpg\").",
|
||||
Required: true,
|
||||
PlanModifiers: requiresReplace,
|
||||
},
|
||||
"name": schema.StringAttribute{
|
||||
Description: "Name of the key.",
|
||||
Required: true,
|
||||
PlanModifiers: requiresReplace,
|
||||
},
|
||||
"algorithm": schema.StringAttribute{
|
||||
Description: "Key algorithm: rsa-2048, rsa-3072, rsa-4096 or ed25519.",
|
||||
Optional: true,
|
||||
Computed: true,
|
||||
Default: stringdefault.StaticString("rsa-3072"),
|
||||
PlanModifiers: requiresReplace,
|
||||
},
|
||||
"identity": schema.StringAttribute{
|
||||
Description: "OpenPGP User ID (e.g. \"Me <me@example>\"). Defaults to the key name.",
|
||||
Optional: true,
|
||||
Computed: true,
|
||||
PlanModifiers: requiresReplace,
|
||||
},
|
||||
"exportable": schema.BoolAttribute{
|
||||
Description: "Allow exporting the private key. Can be enabled later but never disabled.",
|
||||
Optional: true,
|
||||
Computed: true,
|
||||
Default: booldefault.StaticBool(false),
|
||||
},
|
||||
"deletion_allowed": schema.BoolAttribute{
|
||||
Description: "Whether the key may be deleted. Terraform enables this automatically on destroy.",
|
||||
Optional: true,
|
||||
Computed: true,
|
||||
Default: booldefault.StaticBool(false),
|
||||
},
|
||||
"min_decryption_version": schema.Int64Attribute{
|
||||
Description: "Minimum key version usable for decryption and verification.",
|
||||
Optional: true,
|
||||
Computed: true,
|
||||
},
|
||||
"latest_version": schema.Int64Attribute{
|
||||
Description: "The current (highest) key version.",
|
||||
Computed: true,
|
||||
},
|
||||
"fingerprint": schema.StringAttribute{
|
||||
Description: "OpenPGP fingerprint of the latest version.",
|
||||
Computed: true,
|
||||
},
|
||||
"key_id": schema.StringAttribute{
|
||||
Description: "OpenPGP key ID of the latest version.",
|
||||
Computed: true,
|
||||
},
|
||||
"public_key": schema.StringAttribute{
|
||||
Description: "Armored public key of the latest version (import into gpg/pass to encrypt to this key).",
|
||||
Computed: true,
|
||||
},
|
||||
},
|
||||
}
|
||||
}
|
||||
|
||||
func (r *keyResource) Configure(_ context.Context, req resource.ConfigureRequest, resp *resource.ConfigureResponse) {
|
||||
if req.ProviderData == nil {
|
||||
return
|
||||
}
|
||||
client, ok := req.ProviderData.(*vaultClient)
|
||||
if !ok {
|
||||
resp.Diagnostics.AddError("unexpected provider data type", fmt.Sprintf("got %T", req.ProviderData))
|
||||
return
|
||||
}
|
||||
r.client = client
|
||||
}
|
||||
|
||||
func (r *keyResource) Create(ctx context.Context, req resource.CreateRequest, resp *resource.CreateResponse) {
|
||||
var plan keyModel
|
||||
resp.Diagnostics.Append(req.Plan.Get(ctx, &plan)...)
|
||||
if resp.Diagnostics.HasError() {
|
||||
return
|
||||
}
|
||||
|
||||
backend := strings.Trim(plan.Backend.ValueString(), "/")
|
||||
name := plan.Name.ValueString()
|
||||
|
||||
create := map[string]interface{}{
|
||||
"algorithm": plan.Algorithm.ValueString(),
|
||||
"exportable": plan.Exportable.ValueBool(),
|
||||
}
|
||||
if !plan.Identity.IsNull() && !plan.Identity.IsUnknown() && plan.Identity.ValueString() != "" {
|
||||
create["identity"] = plan.Identity.ValueString()
|
||||
}
|
||||
if _, err := r.client.writeKey(ctx, backend, name, create); err != nil {
|
||||
resp.Diagnostics.AddError("failed to create gpg key", err.Error())
|
||||
return
|
||||
}
|
||||
|
||||
if err := r.applyConfig(ctx, backend, name, plan); err != nil {
|
||||
resp.Diagnostics.AddError("failed to configure gpg key", err.Error())
|
||||
return
|
||||
}
|
||||
|
||||
if diags := r.refresh(ctx, backend, name, &plan); diags.HasError() {
|
||||
resp.Diagnostics.Append(diags...)
|
||||
return
|
||||
}
|
||||
resp.Diagnostics.Append(resp.State.Set(ctx, plan)...)
|
||||
}
|
||||
|
||||
func (r *keyResource) Read(ctx context.Context, req resource.ReadRequest, resp *resource.ReadResponse) {
|
||||
var state keyModel
|
||||
resp.Diagnostics.Append(req.State.Get(ctx, &state)...)
|
||||
if resp.Diagnostics.HasError() {
|
||||
return
|
||||
}
|
||||
|
||||
backend := strings.Trim(state.Backend.ValueString(), "/")
|
||||
name := state.Name.ValueString()
|
||||
|
||||
data, err := r.client.readKey(ctx, backend, name)
|
||||
if err != nil {
|
||||
resp.Diagnostics.AddError("failed to read gpg key", err.Error())
|
||||
return
|
||||
}
|
||||
if data == nil {
|
||||
resp.State.RemoveResource(ctx)
|
||||
return
|
||||
}
|
||||
applyKeyData(&state, data)
|
||||
resp.Diagnostics.Append(resp.State.Set(ctx, state)...)
|
||||
}
|
||||
|
||||
func (r *keyResource) Update(ctx context.Context, req resource.UpdateRequest, resp *resource.UpdateResponse) {
|
||||
var plan keyModel
|
||||
resp.Diagnostics.Append(req.Plan.Get(ctx, &plan)...)
|
||||
if resp.Diagnostics.HasError() {
|
||||
return
|
||||
}
|
||||
|
||||
backend := strings.Trim(plan.Backend.ValueString(), "/")
|
||||
name := plan.Name.ValueString()
|
||||
|
||||
if err := r.applyConfig(ctx, backend, name, plan); err != nil {
|
||||
resp.Diagnostics.AddError("failed to update gpg key config", err.Error())
|
||||
return
|
||||
}
|
||||
|
||||
if diags := r.refresh(ctx, backend, name, &plan); diags.HasError() {
|
||||
resp.Diagnostics.Append(diags...)
|
||||
return
|
||||
}
|
||||
resp.Diagnostics.Append(resp.State.Set(ctx, plan)...)
|
||||
}
|
||||
|
||||
func (r *keyResource) Delete(ctx context.Context, req resource.DeleteRequest, resp *resource.DeleteResponse) {
|
||||
var state keyModel
|
||||
resp.Diagnostics.Append(req.State.Get(ctx, &state)...)
|
||||
if resp.Diagnostics.HasError() {
|
||||
return
|
||||
}
|
||||
|
||||
backend := strings.Trim(state.Backend.ValueString(), "/")
|
||||
name := state.Name.ValueString()
|
||||
|
||||
// Ensure deletion is permitted so `terraform destroy` always succeeds.
|
||||
if err := r.client.writeKeyConfig(ctx, backend, name, map[string]interface{}{"deletion_allowed": true}); err != nil {
|
||||
resp.Diagnostics.AddError("failed to allow deletion of gpg key", err.Error())
|
||||
return
|
||||
}
|
||||
if err := r.client.deleteKey(ctx, backend, name); err != nil {
|
||||
resp.Diagnostics.AddError("failed to delete gpg key", err.Error())
|
||||
return
|
||||
}
|
||||
}
|
||||
|
||||
// ImportState accepts "<backend>/<name>".
|
||||
func (r *keyResource) ImportState(ctx context.Context, req resource.ImportStateRequest, resp *resource.ImportStateResponse) {
|
||||
backend, name, found := strings.Cut(req.ID, "/")
|
||||
if !found || backend == "" || name == "" {
|
||||
resp.Diagnostics.AddError("invalid import ID", "expected \"<backend>/<name>\", e.g. \"gpg/app\"")
|
||||
return
|
||||
}
|
||||
resp.Diagnostics.Append(resp.State.SetAttribute(ctx, path.Root("backend"), backend)...)
|
||||
resp.Diagnostics.Append(resp.State.SetAttribute(ctx, path.Root("name"), name)...)
|
||||
}
|
||||
|
||||
// applyConfig pushes the mutable key policy (deletion_allowed / exportable /
|
||||
// min_decryption_version) via keys/<name>/config.
|
||||
func (r *keyResource) applyConfig(ctx context.Context, backend, name string, m keyModel) error {
|
||||
cfg := map[string]interface{}{}
|
||||
if !m.DeletionAllowed.IsNull() && !m.DeletionAllowed.IsUnknown() {
|
||||
cfg["deletion_allowed"] = m.DeletionAllowed.ValueBool()
|
||||
}
|
||||
// exportable can only be turned on, so only send it when true.
|
||||
if !m.Exportable.IsNull() && !m.Exportable.IsUnknown() && m.Exportable.ValueBool() {
|
||||
cfg["exportable"] = true
|
||||
}
|
||||
if !m.MinDecryptionVersion.IsNull() && !m.MinDecryptionVersion.IsUnknown() {
|
||||
cfg["min_decryption_version"] = m.MinDecryptionVersion.ValueInt64()
|
||||
}
|
||||
if len(cfg) == 0 {
|
||||
return nil
|
||||
}
|
||||
return r.client.writeKeyConfig(ctx, backend, name, cfg)
|
||||
}
|
||||
|
||||
// refresh re-reads the key and applies it onto the model (computed fields).
|
||||
func (r *keyResource) refresh(ctx context.Context, backend, name string, m *keyModel) diag.Diagnostics {
|
||||
var diags diag.Diagnostics
|
||||
data, err := r.client.readKey(ctx, backend, name)
|
||||
if err != nil {
|
||||
diags.AddError("failed to read gpg key after write", err.Error())
|
||||
return diags
|
||||
}
|
||||
if data == nil {
|
||||
diags.AddError("gpg key vanished", fmt.Sprintf("key %q not found in backend %q immediately after write", name, backend))
|
||||
return diags
|
||||
}
|
||||
applyKeyData(m, data)
|
||||
return diags
|
||||
}
|
||||
|
||||
// applyKeyData maps an engine key response onto the model.
|
||||
func applyKeyData(m *keyModel, data map[string]interface{}) {
|
||||
if s, ok := toString(data["algorithm"]); ok {
|
||||
m.Algorithm = types.StringValue(s)
|
||||
}
|
||||
if s, ok := toString(data["identity"]); ok {
|
||||
m.Identity = types.StringValue(s)
|
||||
}
|
||||
if b, ok := toBool(data["exportable"]); ok {
|
||||
m.Exportable = types.BoolValue(b)
|
||||
}
|
||||
if b, ok := toBool(data["deletion_allowed"]); ok {
|
||||
m.DeletionAllowed = types.BoolValue(b)
|
||||
}
|
||||
if n, ok := toInt64(data["min_decryption_version"]); ok {
|
||||
m.MinDecryptionVersion = types.Int64Value(n)
|
||||
}
|
||||
if n, ok := toInt64(data["latest_version"]); ok {
|
||||
m.LatestVersion = types.Int64Value(n)
|
||||
}
|
||||
if s, ok := toString(data["fingerprint"]); ok {
|
||||
m.Fingerprint = types.StringValue(s)
|
||||
}
|
||||
if s, ok := toString(data["public_key"]); ok {
|
||||
m.PublicKey = types.StringValue(s)
|
||||
}
|
||||
m.KeyID = types.StringValue(keyIDForLatest(data))
|
||||
}
|
||||
|
||||
// keyIDForLatest digs the latest version's key_id out of the keys map.
|
||||
func keyIDForLatest(data map[string]interface{}) string {
|
||||
latest, ok := toInt64(data["latest_version"])
|
||||
if !ok {
|
||||
return ""
|
||||
}
|
||||
versions, ok := data["keys"].(map[string]interface{})
|
||||
if !ok {
|
||||
return ""
|
||||
}
|
||||
info, ok := versions[fmt.Sprintf("%d", latest)].(map[string]interface{})
|
||||
if !ok {
|
||||
return ""
|
||||
}
|
||||
if s, ok := toString(info["key_id"]); ok {
|
||||
return s
|
||||
}
|
||||
return ""
|
||||
}
|
||||
@@ -0,0 +1,235 @@
|
||||
package provider
|
||||
|
||||
import (
|
||||
"context"
|
||||
"fmt"
|
||||
"strings"
|
||||
|
||||
"github.com/hashicorp/terraform-plugin-framework/path"
|
||||
"github.com/hashicorp/terraform-plugin-framework/resource"
|
||||
"github.com/hashicorp/terraform-plugin-framework/resource/schema"
|
||||
"github.com/hashicorp/terraform-plugin-framework/resource/schema/planmodifier"
|
||||
"github.com/hashicorp/terraform-plugin-framework/resource/schema/stringdefault"
|
||||
"github.com/hashicorp/terraform-plugin-framework/resource/schema/stringplanmodifier"
|
||||
"github.com/hashicorp/terraform-plugin-framework/types"
|
||||
)
|
||||
|
||||
var (
|
||||
_ resource.Resource = &secretBackendResource{}
|
||||
_ resource.ResourceWithImportState = &secretBackendResource{}
|
||||
)
|
||||
|
||||
const defaultPluginType = "vault-plugin-secrets-gpg"
|
||||
|
||||
type secretBackendResource struct {
|
||||
client *vaultClient
|
||||
}
|
||||
|
||||
type secretBackendModel struct {
|
||||
Path types.String `tfsdk:"path"`
|
||||
Plugin types.String `tfsdk:"plugin"`
|
||||
Description types.String `tfsdk:"description"`
|
||||
SHA256 types.String `tfsdk:"sha256"`
|
||||
Command types.String `tfsdk:"command"`
|
||||
}
|
||||
|
||||
func NewSecretBackendResource() resource.Resource {
|
||||
return &secretBackendResource{}
|
||||
}
|
||||
|
||||
func (r *secretBackendResource) Metadata(_ context.Context, req resource.MetadataRequest, resp *resource.MetadataResponse) {
|
||||
resp.TypeName = req.ProviderTypeName + "_secret_backend"
|
||||
}
|
||||
|
||||
func (r *secretBackendResource) Schema(_ context.Context, _ resource.SchemaRequest, resp *resource.SchemaResponse) {
|
||||
resp.Schema = schema.Schema{
|
||||
Description: "Mounts the gpg secrets engine. Optionally registers the plugin in the catalog first when a sha256 is given.",
|
||||
Attributes: map[string]schema.Attribute{
|
||||
"path": schema.StringAttribute{
|
||||
Description: "Mount path for the gpg secrets engine (e.g. \"gpg\").",
|
||||
Required: true,
|
||||
PlanModifiers: []planmodifier.String{
|
||||
stringplanmodifier.RequiresReplace(),
|
||||
},
|
||||
},
|
||||
"plugin": schema.StringAttribute{
|
||||
Description: "Registered plugin name/type to mount.",
|
||||
Optional: true,
|
||||
Computed: true,
|
||||
Default: stringdefault.StaticString(defaultPluginType),
|
||||
PlanModifiers: []planmodifier.String{
|
||||
stringplanmodifier.RequiresReplace(),
|
||||
},
|
||||
},
|
||||
"description": schema.StringAttribute{
|
||||
Description: "Human-readable description of the mount.",
|
||||
Optional: true,
|
||||
Computed: true,
|
||||
Default: stringdefault.StaticString(""),
|
||||
},
|
||||
"sha256": schema.StringAttribute{
|
||||
Description: "SHA-256 of the plugin binary. When set, the plugin is (re)registered in the catalog before mounting; omit if the plugin is already registered out of band.",
|
||||
Optional: true,
|
||||
},
|
||||
"command": schema.StringAttribute{
|
||||
Description: "Plugin binary filename (relative to the server plugin_directory) used when registering. Defaults to the plugin name. Only used when sha256 is set.",
|
||||
Optional: true,
|
||||
Computed: true,
|
||||
},
|
||||
},
|
||||
}
|
||||
}
|
||||
|
||||
func (r *secretBackendResource) Configure(_ context.Context, req resource.ConfigureRequest, resp *resource.ConfigureResponse) {
|
||||
if req.ProviderData == nil {
|
||||
return
|
||||
}
|
||||
client, ok := req.ProviderData.(*vaultClient)
|
||||
if !ok {
|
||||
resp.Diagnostics.AddError("unexpected provider data type", fmt.Sprintf("got %T", req.ProviderData))
|
||||
return
|
||||
}
|
||||
r.client = client
|
||||
}
|
||||
|
||||
// managesPlugin reports whether the resource owns the catalog entry (sha256 set).
|
||||
func managesPlugin(m secretBackendModel) bool {
|
||||
return !m.SHA256.IsNull() && m.SHA256.ValueString() != ""
|
||||
}
|
||||
|
||||
// resolveCommand returns the binary filename to register: explicit command, else
|
||||
// the plugin name.
|
||||
func resolveCommand(m secretBackendModel) string {
|
||||
if !m.Command.IsNull() && !m.Command.IsUnknown() && m.Command.ValueString() != "" {
|
||||
return m.Command.ValueString()
|
||||
}
|
||||
return m.Plugin.ValueString()
|
||||
}
|
||||
|
||||
func (r *secretBackendResource) Create(ctx context.Context, req resource.CreateRequest, resp *resource.CreateResponse) {
|
||||
var plan secretBackendModel
|
||||
resp.Diagnostics.Append(req.Plan.Get(ctx, &plan)...)
|
||||
if resp.Diagnostics.HasError() {
|
||||
return
|
||||
}
|
||||
|
||||
mountPath := strings.Trim(plan.Path.ValueString(), "/")
|
||||
command := resolveCommand(plan)
|
||||
|
||||
if managesPlugin(plan) {
|
||||
if err := r.client.registerPlugin(ctx, plan.Plugin.ValueString(), command, plan.SHA256.ValueString()); err != nil {
|
||||
resp.Diagnostics.AddError("failed to register gpg plugin", err.Error())
|
||||
return
|
||||
}
|
||||
}
|
||||
|
||||
if err := r.client.enableMount(ctx, mountPath, plan.Plugin.ValueString(), plan.Description.ValueString()); err != nil {
|
||||
if isMountAlreadyExists(err) {
|
||||
resp.Diagnostics.AddError(
|
||||
"mount path already in use",
|
||||
fmt.Sprintf("A secrets engine is already mounted at %q. Import it or choose another path.", mountPath),
|
||||
)
|
||||
return
|
||||
}
|
||||
resp.Diagnostics.AddError("failed to enable gpg secrets engine", err.Error())
|
||||
return
|
||||
}
|
||||
|
||||
plan.Path = types.StringValue(mountPath)
|
||||
plan.Command = types.StringValue(command)
|
||||
resp.Diagnostics.Append(resp.State.Set(ctx, plan)...)
|
||||
}
|
||||
|
||||
func (r *secretBackendResource) Read(ctx context.Context, req resource.ReadRequest, resp *resource.ReadResponse) {
|
||||
var state secretBackendModel
|
||||
resp.Diagnostics.Append(req.State.Get(ctx, &state)...)
|
||||
if resp.Diagnostics.HasError() {
|
||||
return
|
||||
}
|
||||
|
||||
mountPath := strings.Trim(state.Path.ValueString(), "/")
|
||||
mount, err := r.client.mountInfo(ctx, mountPath)
|
||||
if err != nil {
|
||||
resp.Diagnostics.AddError("failed to read mount", err.Error())
|
||||
return
|
||||
}
|
||||
if mount == nil {
|
||||
resp.State.RemoveResource(ctx)
|
||||
return
|
||||
}
|
||||
state.Description = types.StringValue(mount.Description)
|
||||
if mount.Type != "" {
|
||||
state.Plugin = types.StringValue(mount.Type)
|
||||
}
|
||||
|
||||
if managesPlugin(state) {
|
||||
info, err := r.client.pluginInfo(ctx, state.Plugin.ValueString())
|
||||
if err != nil {
|
||||
resp.Diagnostics.AddError("failed to read plugin catalog entry", err.Error())
|
||||
return
|
||||
}
|
||||
if info != nil {
|
||||
if info.SHA256 != "" {
|
||||
state.SHA256 = types.StringValue(info.SHA256)
|
||||
}
|
||||
if info.Command != "" {
|
||||
state.Command = types.StringValue(info.Command)
|
||||
}
|
||||
}
|
||||
}
|
||||
|
||||
resp.Diagnostics.Append(resp.State.Set(ctx, state)...)
|
||||
}
|
||||
|
||||
func (r *secretBackendResource) Update(ctx context.Context, req resource.UpdateRequest, resp *resource.UpdateResponse) {
|
||||
var plan, state secretBackendModel
|
||||
resp.Diagnostics.Append(req.Plan.Get(ctx, &plan)...)
|
||||
resp.Diagnostics.Append(req.State.Get(ctx, &state)...)
|
||||
if resp.Diagnostics.HasError() {
|
||||
return
|
||||
}
|
||||
|
||||
mountPath := strings.Trim(state.Path.ValueString(), "/")
|
||||
|
||||
if !plan.Description.Equal(state.Description) {
|
||||
if err := r.client.tuneMount(ctx, mountPath, plan.Description.ValueString()); err != nil {
|
||||
resp.Diagnostics.AddError("failed to tune mount description", err.Error())
|
||||
return
|
||||
}
|
||||
}
|
||||
|
||||
command := resolveCommand(plan)
|
||||
if managesPlugin(plan) && (!plan.SHA256.Equal(state.SHA256) || command != state.Command.ValueString()) {
|
||||
if err := r.client.registerPlugin(ctx, plan.Plugin.ValueString(), command, plan.SHA256.ValueString()); err != nil {
|
||||
resp.Diagnostics.AddError("failed to re-register gpg plugin", err.Error())
|
||||
return
|
||||
}
|
||||
}
|
||||
|
||||
plan.Path = types.StringValue(mountPath)
|
||||
plan.Command = types.StringValue(command)
|
||||
resp.Diagnostics.Append(resp.State.Set(ctx, plan)...)
|
||||
}
|
||||
|
||||
func (r *secretBackendResource) Delete(ctx context.Context, req resource.DeleteRequest, resp *resource.DeleteResponse) {
|
||||
var state secretBackendModel
|
||||
resp.Diagnostics.Append(req.State.Get(ctx, &state)...)
|
||||
if resp.Diagnostics.HasError() {
|
||||
return
|
||||
}
|
||||
|
||||
mountPath := strings.Trim(state.Path.ValueString(), "/")
|
||||
if err := r.client.disableMount(ctx, mountPath); err != nil {
|
||||
resp.Diagnostics.AddError("failed to disable gpg secrets engine", err.Error())
|
||||
return
|
||||
}
|
||||
|
||||
if managesPlugin(state) {
|
||||
// Best effort: the catalog entry may be shared; ignore failures.
|
||||
_ = r.client.deregisterPlugin(ctx, state.Plugin.ValueString())
|
||||
}
|
||||
}
|
||||
|
||||
func (r *secretBackendResource) ImportState(ctx context.Context, req resource.ImportStateRequest, resp *resource.ImportStateResponse) {
|
||||
resource.ImportStatePassthroughID(ctx, path.Root("path"), req, resp)
|
||||
}
|
||||
@@ -0,0 +1,28 @@
|
||||
package main
|
||||
|
||||
import (
|
||||
"context"
|
||||
"flag"
|
||||
"log"
|
||||
|
||||
"github.com/hashicorp/terraform-plugin-framework/providerserver"
|
||||
|
||||
"git.unkin.net/unkin/terraform-provider-gpgvaultsecret/internal/provider"
|
||||
)
|
||||
|
||||
var version = "0.0.1"
|
||||
|
||||
func main() {
|
||||
var debug bool
|
||||
flag.BoolVar(&debug, "debug", false, "enable debug mode")
|
||||
flag.Parse()
|
||||
|
||||
opts := providerserver.ServeOpts{
|
||||
Address: "git.unkin.net/unkin/gpgvaultsecret",
|
||||
Debug: debug,
|
||||
}
|
||||
|
||||
if err := providerserver.Serve(context.Background(), provider.New(version), opts); err != nil {
|
||||
log.Fatal(err)
|
||||
}
|
||||
}
|
||||
Executable
+98
@@ -0,0 +1,98 @@
|
||||
#!/usr/bin/env bash
|
||||
#
|
||||
# End-to-end test for terraform-provider-gpgvaultsecret. Boots a Vault dev server
|
||||
# running the vault-plugin-secrets-gpg engine, then applies real terraform that
|
||||
# registers + mounts the backend, creates a key, and reads it via the data
|
||||
# source. Verifies the outputs and that the mounted engine actually works, then
|
||||
# destroys and confirms cleanup.
|
||||
#
|
||||
set -euo pipefail
|
||||
|
||||
ROOT_DIR="$(cd "$(dirname "${BASH_SOURCE[0]}")/.." && pwd)"
|
||||
PLUGIN_BIN="${PLUGIN_BIN:-${ROOT_DIR}/../vault-plugin-secrets-gpg/dist/vault-plugin-secrets-gpg}"
|
||||
|
||||
red() { printf '\033[31m%s\033[0m\n' "$*"; }
|
||||
green() { printf '\033[32m%s\033[0m\n' "$*"; }
|
||||
blue() { printf '\033[34m==> %s\033[0m\n' "$*"; }
|
||||
fail() { red "FAIL: $*"; exit 1; }
|
||||
|
||||
command -v vault >/dev/null || fail "vault binary not found"
|
||||
command -v terraform >/dev/null || fail "terraform binary not found"
|
||||
[ -x "${PLUGIN_BIN}" ] || fail "plugin binary not found at ${PLUGIN_BIN} (build it: make -C ../vault-plugin-secrets-gpg build)"
|
||||
|
||||
WORK="$(mktemp -d)"
|
||||
PLUGIN_DIR="${WORK}/plugins"
|
||||
mkdir -p "${PLUGIN_DIR}"
|
||||
cp "${PLUGIN_BIN}" "${PLUGIN_DIR}/vault-plugin-secrets-gpg"
|
||||
PLUGIN_SHA="$(sha256sum "${PLUGIN_DIR}/vault-plugin-secrets-gpg" | awk '{print $1}')"
|
||||
|
||||
export VAULT_ADDR="http://127.0.0.1:8282"
|
||||
export VAULT_TOKEN="root"
|
||||
|
||||
cleanup() {
|
||||
[ -n "${VAULT_PID:-}" ] && kill "${VAULT_PID}" 2>/dev/null || true
|
||||
rm -rf "${WORK}"
|
||||
}
|
||||
trap cleanup EXIT
|
||||
|
||||
blue "Building provider"
|
||||
make -C "${ROOT_DIR}" build >/dev/null
|
||||
PROVIDER_BIN="${ROOT_DIR}/terraform-provider-gpgvaultsecret"
|
||||
|
||||
blue "Starting Vault dev server (plugin_directory=${PLUGIN_DIR})"
|
||||
vault server -dev -dev-root-token-id=root -dev-listen-address=127.0.0.1:8282 \
|
||||
-dev-plugin-dir="${PLUGIN_DIR}" >"${WORK}/vault.log" 2>&1 &
|
||||
VAULT_PID=$!
|
||||
for i in $(seq 1 30); do
|
||||
vault status >/dev/null 2>&1 && break
|
||||
sleep 0.5
|
||||
[ "$i" = 30 ] && fail "vault did not become ready"
|
||||
done
|
||||
green "vault ready"
|
||||
|
||||
# Dev override so terraform uses the freshly built provider binary directly.
|
||||
cat > "${WORK}/dev.tfrc" <<EOF
|
||||
provider_installation {
|
||||
dev_overrides {
|
||||
"git.unkin.net/unkin/gpgvaultsecret" = "$(dirname "${PROVIDER_BIN}")"
|
||||
}
|
||||
direct {}
|
||||
}
|
||||
EOF
|
||||
export TF_CLI_CONFIG_FILE="${WORK}/dev.tfrc"
|
||||
|
||||
TFDIR="${ROOT_DIR}/test/e2e"
|
||||
export TF_IN_AUTOMATION=1
|
||||
tfvars=(-var "address=${VAULT_ADDR}" -var "token=root" -var "plugin_sha256=${PLUGIN_SHA}")
|
||||
|
||||
blue "terraform apply"
|
||||
# dev_overrides skips init; apply directly.
|
||||
terraform -chdir="${TFDIR}" apply -auto-approve "${tfvars[@]}" >/dev/null
|
||||
green "apply succeeded"
|
||||
|
||||
fpr="$(terraform -chdir="${TFDIR}" output -raw resource_fingerprint)"
|
||||
pub="$(terraform -chdir="${TFDIR}" output -raw data_public_key)"
|
||||
ver="$(terraform -chdir="${TFDIR}" output -raw latest_version)"
|
||||
[ -n "${fpr}" ] || fail "no fingerprint output"
|
||||
printf '%s' "${pub}" | grep -q 'BEGIN PGP PUBLIC KEY BLOCK' || fail "data source public_key not armored"
|
||||
[ "${ver}" = "1" ] || fail "latest_version != 1 (got ${ver})"
|
||||
green "outputs OK: version=${ver} fpr=${fpr:0:16}..."
|
||||
|
||||
blue "engine is live: encrypt + decrypt via the mounted backend"
|
||||
ct="$(vault write -field=ciphertext gpg/encrypt/app plaintext="$(printf 'tf-secret' | base64)")"
|
||||
pt="$(vault write -field=plaintext gpg/decrypt/app ciphertext="${ct}" | base64 -d)"
|
||||
[ "${pt}" = "tf-secret" ] || fail "encrypt/decrypt through the tf-managed engine failed"
|
||||
green "encrypt/decrypt OK"
|
||||
|
||||
blue "terraform destroy"
|
||||
terraform -chdir="${TFDIR}" destroy -auto-approve "${tfvars[@]}" >/dev/null
|
||||
if vault secrets list -format=json 2>/dev/null | grep -q '"gpg/"'; then
|
||||
fail "mount still present after destroy"
|
||||
fi
|
||||
green "destroy removed the mount + key"
|
||||
|
||||
# tidy generated state so the tree stays clean
|
||||
rm -f "${TFDIR}"/terraform.tfstate* "${TFDIR}"/.terraform.lock.hcl
|
||||
rm -rf "${TFDIR}"/.terraform
|
||||
|
||||
green "ALL PROVIDER END-TO-END CHECKS PASSED"
|
||||
@@ -0,0 +1,44 @@
|
||||
terraform {
|
||||
required_providers {
|
||||
gpg = {
|
||||
source = "git.unkin.net/unkin/gpgvaultsecret"
|
||||
}
|
||||
}
|
||||
}
|
||||
|
||||
variable "address" { type = string }
|
||||
variable "token" { type = string }
|
||||
variable "plugin_sha256" { type = string }
|
||||
|
||||
provider "gpg" {
|
||||
address = var.address
|
||||
token = var.token
|
||||
}
|
||||
|
||||
# Register the plugin in the catalog (sha256) and mount the engine at gpg/.
|
||||
resource "gpg_secret_backend" "gpg" {
|
||||
path = "gpg"
|
||||
sha256 = var.plugin_sha256
|
||||
description = "GPG/OpenPGP secrets engine"
|
||||
}
|
||||
|
||||
# A managed key.
|
||||
resource "gpg_key" "app" {
|
||||
backend = gpg_secret_backend.gpg.path
|
||||
name = "app"
|
||||
algorithm = "rsa-2048"
|
||||
identity = "App <app@unkin.net>"
|
||||
exportable = false
|
||||
}
|
||||
|
||||
# Read it back via the data source.
|
||||
data "gpg_key" "app" {
|
||||
backend = gpg_secret_backend.gpg.path
|
||||
name = gpg_key.app.name
|
||||
depends_on = [gpg_key.app]
|
||||
}
|
||||
|
||||
output "resource_fingerprint" { value = gpg_key.app.fingerprint }
|
||||
output "resource_public_key" { value = gpg_key.app.public_key }
|
||||
output "data_public_key" { value = data.gpg_key.app.public_key }
|
||||
output "latest_version" { value = gpg_key.app.latest_version }
|
||||
Reference in New Issue
Block a user